New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack
Cybersecurity experts have revealed information on a new campaign called SHADOW#REACTOR, which uses an evasive multi-stage attack chain to create persistent, covert remote access and deliver Remcos RAT, a commercial remote administration tool.
According to a technical report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, the infection chain follows a carefully planned execution path: an obfuscated VBS launcher run via wscript.exe triggers a PowerShell downloader, which retrieves fragmented, text-based payloads from a remote host.
A.NET Reactor-protected assembly reconstructs these pieces into encoded loaders, decodes them in memory, and uses them to retrieve and apply a distant Remcos configuration. The Remcos RAT backdoor i...

