DonutLoader Reloaded: Current RemcosRAT Infection

General News

Summary

G Data analysts describe a new Remcos RAT infection chain that starts with a phishing email carrying a malicious .CMD attachment. The attack uses multiple living-off-the-land binaries, VBScript, PowerShell, AutoIt, and DonutLoader shellcode to stage and inject the payload in memory. The chain downloads legitimate Windows and 7-Zip components, uses obfuscation and password-protected archives, and hides malicious activity inside normal system processes. The final payload is Remcos RAT 7.2.1 Pro, which gives attackers remote control, file access, credential theft, screenshot capture, and additional payload delivery. The analysis highlights how this campaign extends Remcos tactics with more layered stealth and process injection techniques.

Classifications

industries
Telecommunications
applications
ERP & Process Management

AskAI Classifications

Labels
Cybersecurity Software Consumer Security Software SaaS

Linked Companies

McAfee
$100M to $250M
Fortinet
$10M to $25M
G DATA CyberDefense AG
$50M to $100M
Sophos Ltd.
$500M to $1B