The End of the Static Era: Trellix Uncovers Fully Fileless Remcos RAT Campaign
ID: cf24f57a-cc88-5c6d-b418-d80ce8e60663
STIX ID: report--cf24f57a-cc88-5c6d-b418-d80ce8e60663
Feed Name: securityonline.info
Trellix reports a sophisticated fileless Remcos RAT campaign that avoids disk artifacts by using a procurement-themed phishing lure with a JavaScript downloader that fetches an AES-encrypted PowerShell payload; the PowerShell reconstructs a .NET injector in memory which process-hollows aspnet_compiler.exe to run the final payload. The RAT enforces single-instance execution via mutex Rmc-ZOCNDU, buffers keystrokes/clipboard offline to C:\ProgramData\rema\logs.dat if connectivity is lost, resolves Windows APIs at runtime for compatibility, and communicates with C2 over an unencrypted custom TCP protocol, underscoring the need for memory-centric detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
