Remcos RAT Attack Uses Obfuscated Scripts, Trusted Windows Tools
ID: 60a15db3-854a-5a3c-b195-1740ab83b317
STIX ID: report--60a15db3-854a-5a3c-b195-1740ab83b317
Feed Name: GBHackers
This report documents a Remcos RAT phishing campaign where an obfuscated JavaScript payload delivered via a ZIP attachment fetches an encoded PowerShell script (ENCRYPT.ps1) that decodes Base64/XOR blobs, reflectively loads a .NET assembly and an in-memory PE, and abuses aspnet_compiler.exe as a LOLBin to execute and proxy malicious code; active C2 communications to 192.3.27.141:8087, keystroke logging, and multiple IOCs (file hashes, filenames, and a malicious URL) are provided, and defenders are advised to monitor script/PowerShell telemetry, LOLBin behavior, and outbound C2 patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
