Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligenceremote-access-implantdefense-evasion-methodcommand-and-control-method

Phishing Campaigns Deliver Remcos RAT via Obfuscated Scripts and Trusted Services

Updated 2mo agoFirst seen Apr 2, 20265 sources

Researchers reported multiple Remcos RAT campaigns using phishing emails and trusted infrastructure to infect victims while evading detection. In one intrusion chain, a ZIP attachment named MV MERKET COOPER SPECIFICATION.zip delivered an obfuscated JavaScript file that fetched a PowerShell loader from almacensantangel[.]com; the loader then reconstructed and decrypted payloads in memory, including ALTERNATE.dll and Cqeqpvzeia.exe. The malware injected into the legitimate Microsoft .NET utility aspnet_compiler.exe, communicated with 192[.]3[.]27[.]141:8087, and stored captured keystrokes and other data in C:\ProgramData\remcos\logs.dat, leaving few disk artifacts.

A separate campaign used phishing emails that linked to a fake Google Drive sharing page hosted through Google Cloud Storage and the trusted googleapis.com domain, helping the attack bypass email and web filtering. After user interaction, the infection chain used staged JavaScript redirects or downloads, followed by VBScript or PowerShell execution to retrieve the final Remcos payload, which was then injected into a legitimate Windows process through process hollowing, persisted via Windows Registry entries, and opened encrypted command-and-control channels. The activity underscores how attackers are combining living-off-the-land techniques, trusted cloud services, obfuscated scripting, and legitimate Windows binaries to deploy Remcos for surveillance and data theft.

Share:
Phishing Campaigns Deliver Remcos RAT via Obfuscated Scripts and Trusted Services
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 20, 20262mo ago

Researchers detail purchase-order Remcos RAT phishing chain

Hornetsecurity documented a Remcos RAT phishing campaign using purchase-order themed emails and a double-extension archive attachment. The infection chain executed VBS via wscript.exe, launched hidden PowerShell to fetch a fake PNG from nrmlogistics.ro, reconstructed a .NET payload in memory, and communicated with dentalux202.ydns.eu at 94.198.96.165.

Remcos RAT: Full attack chain of the phishing campaign
Apr 9, 20263mo ago

Researchers identify Google Cloud Storage-themed Remcos phishing campaign

Researchers identified a separate multi-stage phishing campaign that abused Google Cloud Storage and the trusted googleapis.com domain to deliver Remcos RAT worldwide. The attack used fake Google Drive-sharing pages, staged script-based delivery, process hollowing, Registry persistence, and encrypted command-and-control communications.

Apr 2, 20263mo ago

Researchers document obfuscated Remcos RAT phishing campaign

Point Wild’s LAT61 Threat Intelligence Team described a multi-stage Remcos RAT campaign delivered through a phishing email with a ZIP attachment containing obfuscated JavaScript. The infection chain used a PowerShell loader, reconstructed payloads in memory, injected into aspnet_compiler.exe, and communicated with a command-and-control server at 192.3.27.141:8087 while storing stolen data in C:\ProgramData\remcos\logs.dat.

Mar 12, 20263mo ago

Breakglass documents four-stage Remcos RAT campaign with exposed staging servers

Breakglass Intelligence reported a four-stage Remcos RAT campaign using business-themed lures such as a JavaScript file named "Purchase Inquiry _.js" to launch PowerShell, decrypt a payload with rotational XOR, load DEV.dll, and hollow aspnet_compiler.exe. The analysis linked 10 related builds over three weeks, identified JS, HTA, and XLS delivery variants, and found exposed operator infrastructure including a live XAMPP staging server and RDP-accessible C2.

RemcosRAT Four-Stage JavaScript Dropper: Rotational XOR, Process Hollowing, and a Staging Server the Operator Forgot to Lock - Breakglass Intelligence - Breakglass Intelligence
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

31 LINKEDOpen in app
Affected products
9 linked
WindowsApache Http ServerPowershellWindows Script HostPhpGoogle DriveGoogle DriveOpensslXampp
Organizations
18 linked
HornetsecuritySarensGoogleMicrosoft CorporationAny.RunLinkedinColoCrossingXHostPapaCyber Security Newsabuse.chPoint WildBreaking SecurityMajestic HostingBreakglass IntelligenceDataClubIntegrate TI FeedsBreakingSecurity.net
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Phishing Campaigns Deliver Remcos RAT via Obfuscated Scripts and Trusted Services | Mallory