logo

RemcosRAT Distributed Using Steganography

ID: aec36a57-652a-5ee2-9a1a-7f27419b03a9

STIX ID: report--aec36a57-652a-5ee2-9a1a-7f27419b03a9

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-05-08

Date Updated: 2026-04-26

Author: Vanish

...
...

AhnLab ASEC details an active campaign delivering Remcos RAT via Word template injection and an RTF exploit of the Equation Editor (EQNEDT32.EXE). The chain uses obfuscated VBScript and PowerShell to extract a Base64-encoded .NET DLL embedded in a JPEG (steganography), which is reflectively loaded and executed via process hollowing (RegAsm.exe), resulting in RemcosRAT execution; the report includes file detections, behavior signatures, MD5 hashes, C2 URLs and IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.