AsyncRAT and Remcos Delivered in Multi-Stage Phishing Campaign

Reported 24 Jun 2026 by otx · Severity: medium

A global phishing campaign targets business functions with emails carrying malicious Excel attachments that initiate a multi-stage infection chain when macros are enabled. The attack uses layered obfuscation, including HTA scripts, PowerShell, encoded payloads, and steganography