logo

New RAT in Macro-Based Docs Using AppLocker Bypass

ID: 3ac62881-cb79-56b8-96a5-bcdddcb3397a

STIX ID: report--3ac62881-cb79-56b8-96a5-bcdddcb3397a

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes a low-volume targeted campaign (Feb–May 2020) that used macro-enabled Word documents themed around London tech events to deliver a previously unobserved .NET RAT dubbed "ShellReset." Malicious macros drop obfuscated C# source, compile it at runtime with csc.exe or msbuild.exe (bypassing AppLocker/Device Guard), and execute a RAT that registers with C2, supports remote shell execution, directory listing, file exfiltration (via AWS upload URLs), screenshot capture, and startup persistence; the report includes file hashes, hosting and C2 domains, API endpoints, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.