New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack

Cybersecurity experts have revealed information on a new campaign called SHADOW#REACTOR, which uses an evasive multi-stage attack chain to create persistent, covert remote access and deliver Remcos RAT, a commercial remote administration tool.

According to a technical report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the infection chain follows a carefully planned execution path: an obfuscated VBS launcher run via wscript.exe triggers a PowerShell downloader, which retrieves fragmented, text-based payloads from a remote host.

A.NET Reactor-protected assembly reconstructs these pieces into encoded loaders, decodes them in memory, and uses them to retrieve and apply a distant Remcos configuration. The Remcos RAT backdoor is fully installed and takes over the compromised machine once read more about New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *