news.mlab.sh
15 results
threat-intel

JavaScript obfuscation: From party trick to phishing kit

This article from Cisco Talos explores the techniques used to obfuscate JavaScript code, primarily for malicious purposes like phishing and malware delivery. The author details various methods of hiding code, including string manipulation, identifier renaming, runtime decoding, and control-flow flattening. They emphasi…

Cisco Talos · 3d ago High
ransomware

From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execu…

SANS Internet Storm Center · Jun 16, 2026 High