logo

Multi-Stage Steganographic Loader Deploys Remcos RAT and Multiple Infostealers Globally

ID: 633f2f25-6187-5e97-9580-1f7cd1f6573d

STIX ID: report--633f2f25-6187-5e97-9580-1f7cd1f6573d

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Mayura Kathir

...
...

A phishing campaign delivered a packed, unsigned 32-bit .NET executable disguised as a GST/tax-related file which uses resource-based steganography to smuggle an in-memory second-stage loader that reconstructs and executes Remcos RAT. The chain avoids disk writes (AppDomain.Load), uses process hollowing and UAC bypass, gathers credentials and system data, and exfiltrates to hardcoded C2s (e.g., 62.102.148.212); defenders are advised to enable in-memory EDR visibility, block known C2s, enforce application control and scan archives for steganographic artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.