Revamped Remcos RAT Deployed Against Microsoft Windows Users
ID: d6787e2e-e659-531c-a49b-5b85838c46d6
STIX ID: report--d6787e2e-e659-531c-a49b-5b85838c46d6
Feed Name: Dark Reading
Date Published: 2024-11-11
Date Updated: 2026-04-21
Author: Becky Bracken, Senior Editor, Dark Reading
Fortinet researchers describe a phishing campaign that delivers a heavily obfuscated Remcos RAT by exploiting CVE-2017-0199 in unpatched Microsoft Office/WordPad documents; the attack uses multiple scripting layers (JavaScript, VBScript, PowerShell), Base64/URL encoding, fileless in-memory execution of the RAT, and anti-analysis techniques (ZwSetInformationThread, API hooking) to achieve remote control. Recommended defenses include patching Office, advanced email filtering, modern endpoint protections to detect suspicious PowerShell behavior, and regular user security awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
