PULSE NAME
Fileless Execution: PowerShell Based Shellcode Loader Executes Remcos RAT
WHITE AlienVault 2025-05-15 Modified: 2025-05-15
9
IOCs
LOW VOLUME
A new PowerShell-based shellcode loader has been discovered, designed to execute a variant of Remcos RAT. The attack chain begins with malicious LNK files in ZIP archives, using mshta.exe for initial execution. The loader employs fileless techniques, executing code directly in memory to evade traditional defenses. It leverages Windows APIs to allocate memory and execute binary code. The Remcos RAT provides full system control, featuring keylogging, screen capture, and credential theft capabilities. It uses advanced evasion techniques like process hollowing and UAC bypass. The malware establishes persistence through registry modifications and connects to a command and control server over TLS. This sophisticated attack emphasizes the need for behavioral analytics and proactive security measures to detect and mitigate such stealthy threats.
Indicators of Compromise (3 / 9 total)
All FileHash-MD5 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 85dcc4bafccb5b9e255f75c2cd96fec1b4a5b30d09ae0d8eb571b312511d7df7 2025-05-15
FileHash-SHA256 ab8caac901b477c08934ec63978400eb369efb655114805ccba28c48272e5dad 2025-05-15
FileHash-SHA256 ce5ee4a1991fa0a9030dc9e2e0601dc0f14c7961e6550921d8fd2cc4ec53a042 2025-05-15