logo

The End of the Static Era: Trellix Uncovers Fully Fileless Remcos RAT Campaign

ID: cf24f57a-cc88-5c6d-b418-d80ce8e60663

STIX ID: report--cf24f57a-cc88-5c6d-b418-d80ce8e60663

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Trellix reports a sophisticated fileless Remcos RAT campaign that avoids disk artifacts by using a procurement-themed phishing lure with a JavaScript downloader that fetches an AES-encrypted PowerShell payload; the PowerShell reconstructs a .NET injector in memory which process-hollows aspnet_compiler.exe to run the final payload. The RAT enforces single-instance execution via mutex Rmc-ZOCNDU, buffers keystrokes/clipboard offline to C:\ProgramData\rema\logs.dat if connectivity is lost, resolves Windows APIs at runtime for compatibility, and communicates with C2 over an unencrypted custom TCP protocol, underscoring the need for memory-centric detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.