logo

Threat Group Using Rare Data Transfer Tactic in New RemcosRAT Campaign

ID: a931fb50-5983-50a0-abf5-9a02714c5201

STIX ID: report--a931fb50-5983-50a0-abf5-9a02714c5201

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-01-05

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

*Uptycs researchers report that UNC-0050 is conducting a campaign against Ukrainian government organizations using RemcosRAT delivered via a .lnk → 6.hta → PowerShell infection chain, and employing Windows anonymous pipes to exfiltrate data covertly and evade EDR/antivirus; the activity appears targeted and follows previous mass-phishing distributions of the same RAT.*

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.