logo

PowerShell-Driven Multi-Stage Windows Malware Using Text Payloads

ID: 9c3f97c5-89f9-529a-821a-316277c65cbc

STIX ID: report--9c3f97c5-89f9-529a-821a-316277c65cbc

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SHADOW#REACTOR is a sophisticated multi-stage malware campaign that uses obfuscated VBS to bootstrap large inline PowerShell stagers which fetch architecture-specific text staging files (qpwoe64.txt/qpwoe32.txt), reconstruct and load a .NET assembly protected with .NET Reactor, and ultimately hand off execution to MSBuild to run Remcos RAT entirely in memory; the report details downloader behavior, anti-analysis measures, obfuscated configuration retrieval, and the modular pipeline attackers use to update components and evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.