216.73.217.22

Reloaded in a modern Remcos RAT Infection

· Published 30/05/2026 00:22 · Modified 01/06/2026 09:51

Export JSON

Essential information

Published
30/05/2026 00:22
Modified
01/06/2026 09:51
Tags
2026-05-30 autoit donutloader in-memory execution lolbins phishing process injection remcos rat shellcode
Related entities
4 observables, 16 techniques (mitre), 2 malware

Description

Analysts discovered a new infection chain starting with a batch file executing encoded commands that creates hidden directories and retrieves encrypted payloads. Unlike earlier campaigns relying on PowerShell-hosted .NET loaders, this variant incorporates and -based staging for in-memory payload delivery. The infection begins with a email containing a malicious batch file named Bestellung.CMD. The chain abuses legitimate Windows utilities including cscript.exe and SyncAppvPublishingServer.vbs to execute Base64-encoded payloads. Additional components are downloaded from cloud storage, including 7Zip tools and password-protected archives containing obfuscated JScript. The final payload consists of that injects version 7.2.1 Pro into colorcpl.exe, enabling remote control, credential harvesting, keystroke logging, and additional payload deployment.

External references