logo

From Email to RAT: Deciphering a VB Script-Driven Campaign

ID: e6a80f23-36a3-5cf0-a0ea-affb0250dc0d

STIX ID: report--e6a80f23-36a3-5cf0-a0ea-affb0250dc0d

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2024-01-17

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs documents a global, multi-stage VBS-led malware campaign that leverages heavily obfuscated Visual Basic scripts and staged PowerShell to fetch and execute reflectively loaded shellcode, ultimately injecting and running Remcos RAT (and distributing AgentTesla, GuLoader, Xworm, Lokibot); the report provides technical disassembly of each stage, IOCs (hashes, URLs, IPs, mutex) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.