Shadow#Reactor Uses Text Files to Deliver Remcos RAT
ID: 18c79db7-faab-5983-9078-16b239c2d66e
STIX ID: report--18c79db7-faab-5983-9078-16b239c2d66e
Feed Name: Dark Reading
Securonix researchers detail the Shadow#Reactor campaign which uses VBS launchers to trigger heavily obfuscated PowerShell that retrieves fragmented text payloads, which are reassembled and decoded in memory (via MSBuild) to deploy the Remcos RAT; the report highlights living‑off‑the‑land techniques, indicators such as wscript.exe spawning powershell.exe with large inline commands and execution from user-writable directories, opportunistic targeting of enterprises and SMBs, and recommended mitigations including user education, EDR hardening, and PowerShell telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
