Beware the ClickFix Trap: REMCOS RAT Hiding in “Helpful” PUAs
ID: 1cd0d38e-619c-5b0c-9825-1284145262f4
STIX ID: report--1cd0d38e-619c-5b0c-9825-1284145262f4
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
Cybereason GSOC observed a rise in REMCOS RAT infections delivered via trojanized Shotcut portable ZIPs that replace legitimate DLLs to load multi-stage loaders; attackers use MSHTA/PowerShell staging, DLL sideloading, callback-style shellcode injection, and in-memory loading to deploy a full-featured RAT capable of keylogging, credential theft, surveillance, privilege escalation, and persistent C2 communications, with identified IOCs and containment recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
