216.73.217.22

From Inbox to Intrusion: Multi‑Stage Remcos RAT and C2‑Delivered Payloads in Network

· Published 01/04/2026 13:16 · Modified 01/04/2026 15:26

Export JSON

Essential information

Published
01/04/2026 13:16
Modified
01/04/2026 15:26
Tags
2026-04-01 js dropper phishing rat remcos remote access trojan
Related entities
2 observables, 1 malware, 2 others

Description

This multi-stage fileless attack leverages a -delivered JavaScript dropper to trigger a reflective PowerShell loader that executes payloads entirely in memory. The infection chain utilizes obfuscation techniques like rotational XOR and Base64 encoding to reconstruct .NET payloads, significantly reducing the disk-based detection footprint. Stealth is maintained by using aspnet_compiler.exe as a LOLBin to proxy malicious execution and dynamically retrieving the final payload from a remote C2 server.

External references