Threats Tagged 'bat scripts'
View all threats tagged with 'bat scripts'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bat scripts'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated malware campaign has been uncovered that utilizes various techniques to deliver Remote Access Trojans (RATs) such as XWorm and Remcos. The attack chain begins with a ZIP archive, often hosted on trusted platforms like ImgKit, containing obfuscated BAT scripts. These scripts execute PowerShell-based loaders that inject RAT payloads directly into memory, enabling fileless execution. The campaign also employs SVG files with embedded JavaScript to trigger the malware download, exploiting non-traditional file formats to evade detection. The infection process involves multiple stages, including persistence mechanisms, PowerShell script execution, and the use of loaders to decrypt and deploy the final payload. This evolving threat landscape highlights the need for advanced security measures to counter such sophisticated attacks. Join the discussion | AlienVault OTX General | 09/11/2025, 16:40:48 UTC Added: 09/11/2025, 17:15:59 UTC |
Showing 1 to 1 of 1 result