Remcos RAT Malware Disguised as Major Carrier’s Waybill
ID: bb0dffe1-78b3-5c64-9748-24fc69f8fc1a
STIX ID: report--bb0dffe1-78b3-5c64-9748-24fc69f8fc1a
Feed Name: ASEC
**Executive Summary:** AhnLab ASEC reports a phishing campaign distributing Remcos RAT through a malicious HTML attachment that generates obfuscated JavaScript and AutoIt components; the chain decodes an embedded Remcos binary, achieves persistence via autorun registry entries, and injects the RAT into a legitimate RegSvcs.exe process for remote access and data theft. The analysis includes technical details of the injection sequence, persistence and evasion checks, and provides MD5 hashes and a C2 URL as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
