news.mlab.sh
1 result
ransomware

From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execute a reconstructed PowerShell script, ultimately downloading and executing the Remcos RAT. This tech…

SANS Internet Storm Center · Jun 16, 2026 High