PULSE NAME
Fileless Execution: PowerShell Based Shellcode Loader Executes Remcos RAT
WHITE AlienVault 2025-05-15 Modified: 2025-05-15
9
IOCs
LOW VOLUME
A new PowerShell-based shellcode loader has been discovered, designed to execute a variant of Remcos RAT. The attack chain begins with malicious LNK files in ZIP archives, using mshta.exe for initial execution. The loader employs fileless techniques, executing code directly in memory to evade traditional defenses. It leverages Windows APIs to allocate memory and execute binary code. The Remcos RAT provides full system control, featuring keylogging, screen capture, and credential theft capabilities. It uses advanced evasion techniques like process hollowing and UAC bypass. The malware establishes persistence through registry modifications and connects to a command and control server over TLS. This sophisticated attack emphasizes the need for behavioral analytics and proactive security measures to detect and mitigate such stealthy threats.
Indicators of Compromise (4 / 9 total)
All FileHash-MD5 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1b26f7e369e39312e4fcbc993d483b17 2025-05-15
FileHash-MD5 b63178f562b948b850f4676d4b8db1c0 2025-05-15
FileHash-MD5 bf32ff64ac0cfee67f4b2df27733576a 2025-05-15
FileHash-MD5 dd7f049a4b573cc48e0412902a2c14b5 2025-05-15