logo

How attackers built a RAT on a Windows machine using its own .NET compiler

ID: 09706269-aab7-5604-b60e-63774398b928

STIX ID: report--09706269-aab7-5604-b60e-63774398b928

Feed Name: Heimdal Security Blog

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-08-06

Author: Danny Mitchell

...
...

A UK medical-practice endpoint was compromised in May 2026 when an attacker used PowerShell and the .NET compiler to build and execute a Remcos RAT on-host (compile-after-delivery / fileless techniques), evading signature AV; recurring DNS beaconing to a malicious domain was detected and blocked by DNS filtering, which contained the C2 channel. The report maps the chain to MITRE ATT&CK techniques, highlights failures (execution policy, lack of application control, endpoints running as SYSTEM), and recommends layered controls—AppLocker/WDAC, constrained language mode, AMSI/script block logging, least privilege, and DNS filtering—to prevent or detect similar intrusions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.