logo

Stealthy New Remcos RAT Variant Evades Detection Using Innovative Staging Layers

ID: 05a7ba72-8c62-5a96-b6e4-c34f62b8d722

STIX ID: report--05a7ba72-8c62-5a96-b6e4-c34f62b8d722

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Do Son

...
...

Security researchers disclosed a sophisticated phishing campaign delivering a Remcos RAT variant that hides malicious activity by abusing legitimate Windows administration components (e.g., SyncAppvPublishingServer.vbs) and a batch attachment (Bestellung.CMD); the attack stages payloads from cloud storage, drops helper tools and obfuscated configs, and ultimately executes an in-memory DonutLoader shellcode to evade traditional detection. The report highlights indicators and TTPs and recommends blocking unapproved scripts, monitoring native binary arguments, and restricting outbound connections to untrusted cloud storage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.