logo

Shadow#Reactor Uses Text Files to Deliver Remcos RAT

ID: 18c79db7-faab-5983-9078-16b239c2d66e

STIX ID: report--18c79db7-faab-5983-9078-16b239c2d66e

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

Securonix researchers detail the Shadow#Reactor campaign which uses VBS launchers to trigger heavily obfuscated PowerShell that retrieves fragmented text payloads, which are reassembled and decoded in memory (via MSBuild) to deploy the Remcos RAT; the report highlights living‑off‑the‑land techniques, indicators such as wscript.exe spawning powershell.exe with large inline commands and execution from user-writable directories, opportunistic targeting of enterprises and SMBs, and recommended mitigations including user education, EDR hardening, and PowerShell telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.