PowerShell-Driven Multi-Stage Windows Malware Using Text Payloads
ID: 9c3f97c5-89f9-529a-821a-316277c65cbc
STIX ID: report--9c3f97c5-89f9-529a-821a-316277c65cbc
Feed Name: GBHackers
SHADOW#REACTOR is a sophisticated multi-stage malware campaign that uses obfuscated VBS to bootstrap large inline PowerShell stagers which fetch architecture-specific text staging files (qpwoe64.txt/qpwoe32.txt), reconstruct and load a .NET assembly protected with .NET Reactor, and ultimately hand off execution to MSBuild to run Remcos RAT entirely in memory; the report details downloader behavior, anti-analysis measures, obfuscated configuration retrieval, and the modular pipeline attackers use to update components and evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
