Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

0
Medium
Published: 07/17/2026 (07/17/2026, 11:18:30 UTC)
Source: AlienVault OTX General

Description

A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/18/2026, 11:11:51 UTC

Technical Analysis

This threat involves a multi-stage infection chain initiated by a phishing campaign themed around GST refund notifications targeting Indian entities. The initial vector is a malicious RAR archive containing a .NET executable that conceals payloads using bitmap-based steganography. The infection progresses through stages involving DLLs such as Windows Health Optimizer Plus.dll and perfgurd.dll, culminating in the in-memory deployment of Remcos RAT. Persistence is achieved through PowerShell scripts and registry changes. The command-and-control infrastructure leverages dynamic DNS with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT provides capabilities including remote command execution, keylogging, credential harvesting, file manipulation, and extensive system reconnaissance. The campaign is financially motivated and specifically targets Indian businesses and taxpayers.

Potential Impact

The deployed Remcos RAT enables attackers to execute remote commands, log keystrokes, harvest credentials, manipulate files, and perform comprehensive reconnaissance on infected systems. This can lead to data theft, unauthorized access, and potential financial loss for targeted organizations and individuals. The infection chain uses fileless execution techniques and persistence mechanisms that complicate detection and removal.

Defensive Guidance

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Defenders should be aware of phishing campaigns impersonating GST refund notifications and avoid opening unsolicited RAR archives or executables. Monitoring for indicators such as the identified hashes and suspicious PowerShell activity may aid detection. Since the malware uses fileless execution and registry persistence, endpoint detection and response solutions with behavioral analysis capabilities are recommended. No official fix or patch is currently indicated.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.seqrite.com/blog/behind-the-refund-from-gst-phishing-to-remcos-rat-through-a-multi-stage-net-infection-chain/"]
Adversary
null
Pulse Id
6a5a0f86e175ec219dfa17b2
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash07d7d21c2c0920d198efb9ea54900a80
hash20476f3a51dfddf3dc0603fc7858d894
hash2a34bdd25b404737ee5d3b52bf0b3b70
hash3757dccb2adae65ccdf8d5e5c948b927
hash7842d12d9e37c75076133be5b9904cb2
hashcc34d9760394104ad47877a0d57e9c63

Threat ID: 6a5b3f7634329bf928c66a9e

Added to database: 07/18/2026, 08:55:18 UTC

Last enriched: 07/18/2026, 11:11:51 UTC

Last updated: 08/16/2026, 12:11:35 UTC

Views: 110

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses