logo

SHADOW#REACTOR Campaign Uses Text-Only Staging to Deploy Remcos RAT

ID: c9c011b8-a618-56fb-a9e5-940596c951d7

STIX ID: report--c9c011b8-a618-56fb-a9e5-940596c951d7

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

...
...

Securonix researchers describe the SHADOW#REACTOR campaign: a sophisticated, multi-stage Windows infection chain that uses obfuscated VBS to launch encoded PowerShell, repeatedly fetches text-hosted payload fragments which are reassembled and loaded reflectively by a .NET Reactor-protected loader, and abuses trusted Windows binaries (MSBuild.exe) to ultimately deploy the Remcos RAT in memory; defenders are advised to monitor script execution paths and outbound HTTP from scripting engines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.