Fileless Remcos RAT Hijacks Trusted Windows Tools
ID: 0350e30b-1306-5847-b2fa-cf75545adbf3
STIX ID: report--0350e30b-1306-5847-b2fa-cf75545adbf3
Feed Name: securityonline.info
Threat Score
Lat61 reports a sophisticated, multi-stage fileless Remcos RAT campaign that begins with a phishing ZIP containing an obfuscated JavaScript dropper; the script downloads an encrypted PowerShell reflective loader (ENCRYPT.Ps1) that reconstructs the payload entirely in memory, leverages aspnet_compiler.exe as a LOLBin to proxy execution, contacts a C2 at 192.3.27.141:8087, and conducts keystroke/screen/audio surveillance, credential harvesting, and data staging for exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
