logo

New Campaign Uses Remcos RAT to Exploit Victims

ID: d95598e9-6da6-5de0-b983-d6af63bfcd75

STIX ID: report--d95598e9-6da6-5de0-b983-d6af63bfcd75

Feed Name: Fortinet Blog

Threat Score
75/100

Date Published: 2024-11-08

Date Updated: 2026-04-27

...
...

Fortinet FortiGuard Labs documents a phishing campaign that weaponizes an Excel file exploiting CVE-2017-0199 to download an HTA and a downloader (dllhost.exe) which uses obfuscated PowerShell, process hollowing and in-memory deployment to execute a fileless variant of the Remcos RAT; the report details anti-analysis techniques, persistence, Remcos configuration and C2 protocol, and provides URLs, C2 IP:port, and SHA-256 sample hashes along with Fortinet detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.