logo

Obfuscated VBS and PNG Loaders Power New Open Directory Malware Campaign with RAT Payloads

ID: e457d79c-6181-5796-8435-99d24de7cf8e

STIX ID: report--e457d79c-6181-5796-8435-99d24de7cf8e

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

### Executive summary LevelBlue SpiderLabs investigated a scalable, multi-stage malware campaign that used obfuscated VBS scripts as entry points, fileless PowerShell loaders that fetched PNG files containing Base64-encoded .NET assemblies executed in memory, and hosted reusable payloads (including Remcos RAT and privilege-escalation DLLs) in open directories and cloud infrastructure to maximize stealth and rapid payload rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.