logo

Remcos RAT Distributed as UUEncoding (UUE) File

ID: db72964b-d32b-5a89-b551-4765f4f74851

STIX ID: report--db72964b-d32b-5a89-b551-4765f4f74851

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-06-11

Date Updated: 2026-04-26

Author: kwonxx

...
...

AhnLab ASEC identified a phishing campaign delivering Remcos RAT via UUE-encoded VBS attachments (distributed in Power Archiver archives). The VBS drops obfuscated PowerShell scripts that download additional binaries from http://194.59.30.90, inject shellcode into wab.exe, add registry persistence, and execute Remcos which gathers system info and keylogs before exfiltration to duckdns C2 domains; the report includes IPs, domains, and MD5 hashes as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.