logo

Weaponized Shipping Documents Spread Remcos RAT in Stealthy Malware Campaign

ID: 689fdac5-244c-5279-b37f-a0f330d97158

STIX ID: report--689fdac5-244c-5279-b37f-a0f330d97158

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A targeted phishing campaign impersonating Vietnamese shipping companies delivers a fileless Remcos RAT by using Word documents that load a remote RTF exploiting CVE-2017-11882; the RTF executes shellcode which runs a VBScript containing Base64-encoded PowerShell that downloads a .NET module (hidden in an image) to persist via Task Scheduler and inject the Remcos agent into memory using process hollowing, providing extensive surveillance and remote-control capabilities while evading file-based detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.