216.73.216.6

SHADOW#REACTOR – Text-Only Staging, .NET Reactor, and In-Memory Remcos RAT Deployments

· Published 13/01/2026 16:17 · Modified 13/01/2026 16:31

Export JSON

Essential information

Published
13/01/2026 16:17
Modified
13/01/2026 16:31
Tags
.net reactor 2026-01-13 in-memory execution living-off-the-land binaries msbuild abuse obfuscation powershell reflective loading remcos rat text-only staging vbs
Related entities
12 observables, 8 techniques (mitre), 1 malware

Description

This analysis examines a multi-stage Windows malware campaign called SHADOW#REACTOR. The infection chain uses obfuscated , downloaders, and text-based payloads to deliver a backdoor. Key features include fragmented text staging, .NET Reactor protection, , and as a living-off-the-land binary. The campaign leverages complex and to evade detection while establishing persistent remote access. Defensive recommendations focus on script execution monitoring, LOLBin abuse detection, and enhanced logging to counter the sophisticated evasion techniques employed.

External references