RemcosRAT Distributed Using Steganography
ID: aec36a57-652a-5ee2-9a1a-7f27419b03a9
STIX ID: report--aec36a57-652a-5ee2-9a1a-7f27419b03a9
Feed Name: ASEC
Threat Score
AhnLab ASEC details an active campaign delivering Remcos RAT via Word template injection and an RTF exploit of the Equation Editor (EQNEDT32.EXE). The chain uses obfuscated VBScript and PowerShell to extract a Base64-encoded .NET DLL embedded in a JPEG (steganography), which is reflectively loaded and executed via process hollowing (RegAsm.exe), resulting in RemcosRAT execution; the report includes file detections, behavior signatures, MD5 hashes, C2 URLs and IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
