How attackers built a RAT on a Windows machine using its own .NET compiler
ID: 09706269-aab7-5604-b60e-63774398b928
STIX ID: report--09706269-aab7-5604-b60e-63774398b928
Feed Name: Heimdal Security Blog
A UK medical-practice endpoint was compromised in May 2026 when an attacker used PowerShell and the .NET compiler to build and execute a Remcos RAT on-host (compile-after-delivery / fileless techniques), evading signature AV; recurring DNS beaconing to a malicious domain was detected and blocked by DNS filtering, which contained the C2 channel. The report maps the chain to MITRE ATT&CK techniques, highlights failures (execution policy, lack of application control, endpoints running as SYSTEM), and recommends layered controls—AppLocker/WDAC, constrained language mode, AMSI/script block logging, least privilege, and DNS filtering—to prevent or detect similar intrusions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
