From a VHDX File to a Remcos RAT, (Tue, Jun 16th)
ID: df0a38c6-2bab-5863-bc17-90477b6ac7d1
STIX ID: report--df0a38c6-2bab-5863-bc17-90477b6ac7d1
Feed Name: SANS ISC Diary
This report details a multi-stage malware campaign delivering the Remcos RAT: an email ZIP containing a VHDX auto-mounts a malicious JavaScript that launches obfuscated PowerShell via WMI, reconstructs and executes staged payloads (including a .NET reflective loader and shellcode), downloads the final Remcos binary, injects it into backgroundTaskHost.exe, and establishes persistence and C2 communication. The analysis includes file hashes, download URLs, C2 hostname/port, and explains evasion techniques (disk-image container, commented/obfuscated JS, string pollution and XOR/Base64 decoding).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
