Reloaded in a modern Remcos RAT Infection
Essential information
- Published
- 30/05/2026 00:22
- Modified
- 01/06/2026 09:51
- Tags
- 2026-05-30 autoit donutloader in-memory execution lolbins phishing process injection remcos rat shellcode
- Related entities
- 4 observables, 16 techniques (mitre), 2 malware
Description
Analysts discovered a new Remcos RAT infection chain starting with a batch file executing encoded commands that creates hidden directories and retrieves encrypted payloads. Unlike earlier campaigns relying on PowerShell-hosted .NET loaders, this variant incorporates DonutLoader shellcode and AutoIt-based staging for in-memory payload delivery. The infection begins with a phishing email containing a malicious batch file named Bestellung.CMD. The chain abuses legitimate Windows utilities including cscript.exe and SyncAppvPublishingServer.vbs to execute Base64-encoded payloads. Additional components are downloaded from cloud storage, including 7Zip tools and password-protected archives containing obfuscated JScript. The final payload consists of DonutLoader shellcode that injects Remcos RAT version 7.2.1 Pro into colorcpl.exe, enabling remote control, credential harvesting, keystroke logging, and additional payload deployment.