~Asec~
Malicious VBScript and obfuscated PowerShell deliver Remcos RAT via Google Drive.
-
IOCs: 102[.]220[.]160[.]104:2404, drive[.]google[.]com, af87821d3cb4f1d72bfb8002437593ec
-
#Phishing #Remcos #ThreatIntel

~Asec~
Malicious VBScript and obfuscated PowerShell deliver Remcos RAT via Google Drive.
-
IOCs: 102[.]220[.]160[.]104:2404, drive[.]google[.]com, af87821d3cb4f1d72bfb8002437593ec
-
#Phishing #Remcos #ThreatIntel
~Asec~
CVE-2017-0199-laced XLS attachments use HTA and PowerShell to deliver Remcos RAT.
-
IOCs: 172[.]245[.]209[.]133, muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev, blessedongrace[.]duckdns[.]org:19700
-
#Phishing #Remcos #ThreatIntel
A fake purchase-request XLS hides Remcos RAT inside a PNG image. https://intel.threadlinqs.com/threat/TL-2026-2764 #ThreatIntel #CVE_2017_0199 #Remcos #NET
#remcos #powershell (albeit broken) #opendir at:
c2
dmsi.duckdns\.org:14642
9d9f149a0052999587be2078375bb4530b351f3cda1b343c7f81a5d13b02ac45
— from @James_inthe_box (https://x.com/James_inthe_box/status/2104570898124812499)
#remcos #powershell (albeit broken) #opendir at:
https:// delphiaonline\\.top
c2
dmsi\\.duckdns\\.org:14642
9d9f149a0052999587be2078375bb4530b351f3cda1b343c7f81a5d13b02ac45
KREMLIN malware forges Chrome's own integrity checks to sneak in a spyware extension. https://intel.threadlinqs.com/threat/TL-2026-2544 #ThreatIntel #KREMLIN #PULSAR #REMCOS
KREMLIN malware forges Chrome's own tamper checks to sneak in a spy extension that steals your bank logins. https://intel.threadlinqs.com/threat/TL-2026-2525 #ThreatIntel #PULSAR #REMCOS #DonutLoader
Two rival nation-states hacked the same police portal - and never noticed each other. https://intel.threadlinqs.com/threat/TL-2026-2343 #ThreatIntel #PlugX #ShadowPad #Remcos