ransomware From a VHDX File to a Remcos RAT, (Tue, Jun 16th) A malicious ZIP archive, containing a VHDX file, was discovered utilizing a multi-stage attack chain to deploy the Remcos RAT. The initial delivery involves a JavaScript payload that leverages WMI and PowerShell to execute a reconstructed PowerShell script, ultimately downloading and executing the Remcos RAT. This tech… SANS Internet Storm Center · Jun 16, 2026 High DEratpowershellwmi