Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain
A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t...
AI Analysis
Technical Summary
This threat involves a multi-stage infection chain initiated by a phishing campaign themed around GST refund notifications targeting Indian entities. The initial vector is a malicious RAR archive containing a .NET executable that conceals payloads using bitmap-based steganography. The infection progresses through stages involving DLLs such as Windows Health Optimizer Plus.dll and perfgurd.dll, culminating in the in-memory deployment of Remcos RAT. Persistence is achieved through PowerShell scripts and registry changes. The command-and-control infrastructure leverages dynamic DNS with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT provides capabilities including remote command execution, keylogging, credential harvesting, file manipulation, and extensive system reconnaissance. The campaign is financially motivated and specifically targets Indian businesses and taxpayers.
Potential Impact
The deployed Remcos RAT enables attackers to execute remote commands, log keystrokes, harvest credentials, manipulate files, and perform comprehensive reconnaissance on infected systems. This can lead to data theft, unauthorized access, and potential financial loss for targeted organizations and individuals. The infection chain uses fileless execution techniques and persistence mechanisms that complicate detection and removal.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should be aware of phishing campaigns impersonating GST refund notifications and avoid opening unsolicited RAR archives or executables. Monitoring for indicators such as the identified hashes and suspicious PowerShell activity may aid detection. Since the malware uses fileless execution and registry persistence, endpoint detection and response solutions with behavioral analysis capabilities are recommended. No official fix or patch is currently indicated.
Affected Countries
British Indian Ocean Territory, India
Indicators of Compromise
- hash: 07d7d21c2c0920d198efb9ea54900a80
- hash: 20476f3a51dfddf3dc0603fc7858d894
- hash: 2a34bdd25b404737ee5d3b52bf0b3b70
- hash: 3757dccb2adae65ccdf8d5e5c948b927
- hash: 7842d12d9e37c75076133be5b9904cb2
- hash: cc34d9760394104ad47877a0d57e9c63
Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain
Description
A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a multi-stage infection chain initiated by a phishing campaign themed around GST refund notifications targeting Indian entities. The initial vector is a malicious RAR archive containing a .NET executable that conceals payloads using bitmap-based steganography. The infection progresses through stages involving DLLs such as Windows Health Optimizer Plus.dll and perfgurd.dll, culminating in the in-memory deployment of Remcos RAT. Persistence is achieved through PowerShell scripts and registry changes. The command-and-control infrastructure leverages dynamic DNS with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT provides capabilities including remote command execution, keylogging, credential harvesting, file manipulation, and extensive system reconnaissance. The campaign is financially motivated and specifically targets Indian businesses and taxpayers.
Potential Impact
The deployed Remcos RAT enables attackers to execute remote commands, log keystrokes, harvest credentials, manipulate files, and perform comprehensive reconnaissance on infected systems. This can lead to data theft, unauthorized access, and potential financial loss for targeted organizations and individuals. The infection chain uses fileless execution techniques and persistence mechanisms that complicate detection and removal.
Defensive Guidance
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should be aware of phishing campaigns impersonating GST refund notifications and avoid opening unsolicited RAR archives or executables. Monitoring for indicators such as the identified hashes and suspicious PowerShell activity may aid detection. Since the malware uses fileless execution and registry persistence, endpoint detection and response solutions with behavioral analysis capabilities are recommended. No official fix or patch is currently indicated.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.seqrite.com/blog/behind-the-refund-from-gst-phishing-to-remcos-rat-through-a-multi-stage-net-infection-chain/"]
- Adversary
- null
- Pulse Id
- 6a5a0f86e175ec219dfa17b2
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash07d7d21c2c0920d198efb9ea54900a80 | — | |
hash20476f3a51dfddf3dc0603fc7858d894 | — | |
hash2a34bdd25b404737ee5d3b52bf0b3b70 | — | |
hash3757dccb2adae65ccdf8d5e5c948b927 | — | |
hash7842d12d9e37c75076133be5b9904cb2 | — | |
hashcc34d9760394104ad47877a0d57e9c63 | — |
Threat ID: 6a5b3f7634329bf928c66a9e
Added to database: 07/18/2026, 08:55:18 UTC
Last enriched: 07/18/2026, 11:11:51 UTC
Last updated: 08/16/2026, 12:11:35 UTC
Views: 110
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.