Reloaded in a modern Remcos RAT Infection

Reported 30 May 2026 by otx · Severity: medium

Analysts discovered a new Remcos RAT infection chain starting with a batch file executing encoded commands that creates hidden directories and retrieves encrypted payloads. Unlike earlier campaigns relying on PowerShell-hosted .NET loaders, this variant incorporates DonutLoader s