From Inbox to Intrusion: Multi‑Stage Remcos RAT and C2‑Delivered Payloads in Network
Reported 01 Apr 2026 by otx · Severity: medium
This multi-stage fileless Remcos RAT attack leverages a phishing-delivered JavaScript dropper to trigger a reflective PowerShell loader that executes payloads entirely in memory. The infection chain utilizes obfuscation techniques like rotational XOR and Base64 encoding to recons