logo

Fileless Remcos RAT Hijacks Trusted Windows Tools

ID: 0350e30b-1306-5847-b2fa-cf75545adbf3

STIX ID: report--0350e30b-1306-5847-b2fa-cf75545adbf3

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-23

Author: Ddos

...
...

Lat61 reports a sophisticated, multi-stage fileless Remcos RAT campaign that begins with a phishing ZIP containing an obfuscated JavaScript dropper; the script downloads an encrypted PowerShell reflective loader (ENCRYPT.Ps1) that reconstructs the payload entirely in memory, leverages aspnet_compiler.exe as a LOLBin to proxy execution, contacts a C2 at 192.3.27.141:8087, and conducts keystroke/screen/audio surveillance, credential harvesting, and data staging for exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.