Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Reloaded in a modern Remcos RAT Infection

0
Medium
Published: Sat May 30 2026 (05/30/2026, 00:22:49 UTC)
Source: AlienVault OTX General

Description

A new infection chain for Remcos RAT version 7. 2. 1 Pro has been identified, beginning with a phishing email delivering a malicious batch file. This batch file executes encoded commands to create hidden directories and retrieve encrypted payloads. The campaign uses legitimate Windows utilities and incorporates DonutLoader shellcode and AutoIt-based staging to deliver the payload entirely in memory. The final payload injects Remcos RAT into a legitimate Windows process, enabling remote control, credential theft, keystroke logging, and further payload deployment.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 10:03:37 UTC

Technical Analysis

This threat involves a modernized infection chain for Remcos RAT 7.2.1 Pro, initiated by a phishing email containing a batch file (Bestellung.CMD) that runs Base64-encoded commands. Unlike previous campaigns relying on PowerShell .NET loaders, this variant uses DonutLoader shellcode and AutoIt scripts for in-memory execution. The infection abuses legitimate Windows binaries such as cscript.exe and SyncAppvPublishingServer.vbs to execute obfuscated payloads. Additional components, including 7Zip tools and password-protected archives with obfuscated JScript, are downloaded from cloud storage. The final stage injects Remcos RAT into colorcpl.exe, facilitating remote access, credential harvesting, keystroke logging, and deployment of further malicious payloads.

Potential Impact

Successful exploitation results in remote attacker control over the infected system via Remcos RAT, enabling credential theft, keystroke logging, and the ability to deploy additional malware. The use of in-memory execution and process injection techniques complicates detection and mitigation efforts.

Mitigation Recommendations

No official patch or vendor advisory is available for this threat. Patch status is not yet confirmed — check vendor advisories for current remediation guidance. Mitigation should focus on user awareness to prevent phishing infections, restricting execution of unauthorized batch files, and monitoring for abuse of legitimate Windows utilities. Network controls to block access to known cloud storage locations used for payload delivery may also help reduce risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://blog.gdatasoftware.com/2026/05/38426-donutloader-remcos-rat"]
Adversary
null
Pulse Id
6a1a2dd905d9f8c4474cb45e
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash5b3089eefab0e043af8894de86022bdc6df2f42f7098dbd530f42c0ec861d5d8
hash14a0d7978872a2739ac31ef42539e8c708af6afccc5eb74f22fe2b676bfa2df7
hash48bd36c3b8d6a3bf5db4e7b0bbc1692e8cb900475dc7ae16e9f1fa7ba97c8adf
hashb9da295c34accf3632c2c4b6d9e3c74791b4514d27814f79e9bcb77ce168a347

Threat ID: 6a1d5574e29bf47b50d0f564

Added to database: 6/1/2026, 9:48:36 AM

Last enriched: 6/1/2026, 10:03:37 AM

Last updated: 6/1/2026, 4:05:13 PM

Views: 51

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses