logo

Can you use too many LOLBins to drop some RATs?

ID: 37d2f55d-919e-5521-876f-7bab457dfcbc

STIX ID: report--37d2f55d-919e-5521-876f-7bab457dfcbc

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-01-21

Date Updated: 2026-04-28

...
...

This report outlines a multi-stage infection that abused Windows built-in utilities (forfiles, mshta, PowerShell/curl, tar, expand, WScript, reg) to download and stage payloads and ultimately deploy Remcos and an abused NetSupport Manager client as RATs; the chain used fileless download, staged .PART files in C:\ProgramData, a trojanized glaxnimate executable, and stealthy registry persistence. Malwarebytes reportedly blocked the attacker IP and detected the RATs, illustrating both the threat and existing detection capability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.