news.mlab.sh
Back to the feed
ransomware

From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

High
Image: SANS Internet Storm Center
Summary

A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execute a reconstructed PowerShell script, ultimately downloading and executing the Remcos RAT. This technique bypasses traditional security controls by obfuscating the initial stages and utilizing less-monitored methods like WMI and PowerShell.

Read the full article at SANS Internet Storm Center

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.