Threats Tagged 'fileless execution'
View all threats tagged with 'fileless execution'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'fileless execution'
Click on any threat for detailed analysis and mitigation recommendations
Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain 0 A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t... MediumMalware Join the discussion | AlienVault OTX General | 07/17/2026, 11:18:30 UTC Added: 07/18/2026, 08:55:18 UTC |
The TTF Trap: A Global Campaign of a Low-Detection Lua Loader 0 Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration. Join the discussion | AlienVault OTX General | 07/16/2026, 16:06:34 UTC Added: 07/17/2026, 00:32:32 UTC |
Showing 1 to 2 of 2 results