logo

AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

ID: 4bad4f80-3715-54c6-9aae-d94a2fad41d7

STIX ID: report--4bad4f80-3715-54c6-9aae-d94a2fad41d7

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
75/100

Date Published: 2026-07-02

Date Updated: 2026-07-19

Author: LevelBlue SpiderLabs

...
...

LevelBlue SpiderLabs observed a global multi-stage phishing campaign (June 10–23, 2026) using macro-enabled Excel attachments and HTA/PowerShell staging to deliver commodity remote access trojans (Remcos, AsyncRAT) and potentially other infostealers; the report details obfuscation methods, Cloudflare Workers-based staging, fileless execution techniques, representative IOCs, and mapped MITRE ATT&CK techniques to support detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.