logo

Revamped Remcos RAT Deployed Against Microsoft Windows Users

ID: d6787e2e-e659-531c-a49b-5b85838c46d6

STIX ID: report--d6787e2e-e659-531c-a49b-5b85838c46d6

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-11-11

Date Updated: 2026-04-21

Author: Becky Bracken, Senior Editor, Dark Reading

...
...

Fortinet researchers describe a phishing campaign that delivers a heavily obfuscated Remcos RAT by exploiting CVE-2017-0199 in unpatched Microsoft Office/WordPad documents; the attack uses multiple scripting layers (JavaScript, VBScript, PowerShell), Base64/URL encoding, fileless in-memory execution of the RAT, and anti-analysis techniques (ZwSetInformationThread, API hooking) to achieve remote control. Recommended defenses include patching Office, advanced email filtering, modern endpoint protections to detect suspicious PowerShell behavior, and regular user security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.