Phishing emails posing as project quote requests deliver a compressed attachment with VBScript and obfuscated PowerShell, leading to Remcos RAT via Google Drive, UAC bypass, and process injection. #Phishing #RemcosRAT #PowerShell
Explore
Phishing emails posing as project material requests trick victims into opening a malicious XLS file, triggering CVE-2017-0199, a hidden loader chain, and Remcos RAT for data theft. #CVE2017 #RemcosRAT #Korea
