AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign
ID: 4bad4f80-3715-54c6-9aae-d94a2fad41d7
STIX ID: report--4bad4f80-3715-54c6-9aae-d94a2fad41d7
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
LevelBlue SpiderLabs observed a global multi-stage phishing campaign (June 10–23, 2026) using macro-enabled Excel attachments and HTA/PowerShell staging to deliver commodity remote access trojans (Remcos, AsyncRAT) and potentially other infostealers; the report details obfuscation methods, Cloudflare Workers-based staging, fileless execution techniques, representative IOCs, and mapped MITRE ATT&CK techniques to support detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
