Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismremote-access-implantdefense-evasion-methodinitial-access-method

Shadow#Reactor Multi-Stage Windows Malware Delivers Remcos RAT via Text-Based Payload Fragments

Updated 3mo agoFirst seen Jan 13, 20264 sources

Security researchers reported a multi-stage Windows malware campaign dubbed Shadow#Reactor (SHADOW#REACTOR) that uses a VBScript launcher and PowerShell to retrieve fragmented, text-only payloads from remote infrastructure, then reconstructs and executes them to ultimately deploy Remcos RAT. The infection chain relies on user interaction (e.g., phishing/social-engineering lures or compromised web resources) to execute an obfuscated .vbs file via Windows Script Host, after which staged PowerShell downloaders pull encoded payload pieces that are stored as plain text to reduce the likelihood of traditional binary-based detections.

Securonix analysis (as reported in both trade and vendor writeups) describes a modular handoff between stages, including obfuscation layers, base64 decoding patterns, and integrity/size checks to ensure successful reassembly of the final components. The technique emphasizes living-off-the-land execution and flexible staging (allowing attackers to update individual stages independently), with reconstruction activity leveraging legitimate tooling (e.g., MSBuild noted in reporting) before in-memory decoding and retrieval of the final Remcos payload; defenders should treat unusual chains of wscript.exe/cscript.exe spawning PowerShell and subsequent staged text retrieval/reassembly as high-signal behavior for investigation.

Share:
Shadow#Reactor Multi-Stage Windows Malware Delivers Remcos RAT via Text-Based Payload Fragments
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 13, 20265mo ago

Securonix assesses campaign as broad, opportunistic, and unattributed

Researchers said the activity appears to target enterprises and SMBs in a broad 'spray-and-pray' manner consistent with financially motivated operators or possible initial access broker activity. They also stated there was insufficient evidence to attribute the campaign to a known threat actor.

Researchers detail fileless, text-based staging and LOLBin abuse

Technical analysis showed the malware reconstructs payload components from benign-looking text files, decodes .NET assemblies in memory, and uses legitimate Windows tools such as wscript.exe, PowerShell, and MSBuild.exe to reduce on-disk artifacts and evade detection. Securonix also linked the final payload to Remcos RAT through infrastructure tracing and payload signature matching.

Securonix identifies SHADOW#REACTOR delivering Remcos RAT

Securonix researchers reported a newly identified multi-stage Windows malware campaign dubbed SHADOW#REACTOR. The campaign uses an obfuscated VBS launcher, PowerShell, and text-based payload fragments retrieved from remote infrastructure to ultimately deploy Remcos RAT.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Affected products
3 linked
PowershellWindowsWindows Script Host
Organizations
5 linked
SecuronixMicrosoft CorporationDark ReadingAlamyThe Hacker News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Shadow#Reactor Multi-Stage Windows Malware Delivers Remcos RAT via Text-Based Payload Fragments | Mallory