Listen to this Post

In recent months, cybersecurity researchers have detected a troubling spike in attacks involving the Remcos Remote Access Trojan (RAT). Originally designed as a legitimate remote administration tool, Remcos has increasingly been repurposed by threat actors to steal credentials and maintain persistent access to compromised systems. CyberProof’s latest research highlights a wave of sophisticated campaigns during September and October 2025, where attackers leveraged phishing emails, obfuscated scripts, and trusted binaries to bypass traditional security defenses.
Surge of Remcos RAT Infections
CyberProof’s telemetry shows that Remcos RAT accounted for roughly 11% of all infostealer incidents in the last quarter. The malware was primarily delivered via phishing emails containing malicious attachments disguised as corporate order inquiries. A recent example involved an archive named EFEMMAK TURKEY INQUIRY ORDER NR 09162025.gz, which, when extracted, executed a batch file that launched an obfuscated PowerShell loader.
This loader used advanced evasion techniques, employing custom functions like Lotusblo and Garrots to conceal its malicious activity from static analysis tools. Once executed, the script established encrypted TLS 1.2 connections to hxxps://icebergtbilisi.ge/Sluknin.afm to download and decode the Remcos payload entirely in memory—a classic fileless attack method. This approach avoids writing executable files to disk, making it harder for endpoint detection solutions to catch.
Fileless Execution and Trusted Binary Exploitation
The PowerShell loader subsequently invoked msiexec.exe to perform process hollowing, injecting the Remcos payload into RmClient.exe, a legitimate Microsoft binary. By leveraging a trusted system process, attackers bypassed endpoint security measures and minimized alerts. Telemetry confirmed attempts to harvest browser-stored credentials, revealing the primary goal of this campaign: sensitive data exfiltration.
Network Indicators and Attack Infrastructure
Analysis linked the attack to multiple external command-and-control (C2) domains, including ablelifepurelife[.]ydns.eu, ablelifepurelifebk[.]ydns.eu, and icebergtbilisi[.]ge. Temporary payloads were dropped in user profile paths under AppData\Roaming\Hereni, highlighting a pattern of ephemeral file storage. SHA256 hash analysis confirmed the use of specific PowerShell loaders and batch scripts across multiple infection events. Notably, email attachments were localized with German, Polish, and Portuguese variants, signaling a geographically targeted campaign.
Indicators of Compromise
C2 Domains: ablelifepurelife[.]ydns.eu, ablelifepurelifebk[.]ydns.eu, icebergtbilisi[.]ge
Malicious Attachment: EFEMMAK TURKEY INQUIRY ORDER NR 09162025.gz
Attachment Hash: 5eb460204cd0f5510b146b8465b4392e9d0795b5d7fdb51b1c1429f97593a4b3
Batch File: EFEMMAK TURKEY INQUIRY ORDER NR 09162025.bat
Script Hash: 5cb34177d0289e9737e5a261b8d1aac227656b96c768f789d6fcc9bc20adb05e
What Undercode Say: Advanced Tactics Reveal Rising Threat
Remcos RAT exemplifies how legitimate software tools can be weaponized through sophisticated malware campaigns. The use of obfuscated PowerShell scripts and fileless execution illustrates a key trend: attackers are moving away from traditional malware binaries to evade static detection and signature-based defenses. By injecting payloads into trusted system binaries such as RmClient.exe, threat actors exploit implicit trust relationships within the operating system, a method that significantly reduces detection likelihood.
The campaign’s reliance on phishing attachments demonstrates a continued emphasis on social engineering. Attackers carefully craft emails to resemble legitimate business communications, leveraging psychological trust to trick users into executing malicious files. Geographic localization of attachments further indicates targeted attacks rather than random opportunistic campaigns, suggesting attackers are conducting reconnaissance and exploiting regional corporate habits.
From a defensive perspective, organizations must prioritize advanced telemetry monitoring and proactive threat hunting. Detection strategies should include monitoring for abnormal msiexec.exe activity, unusual process hollowing attempts, and fileless execution patterns in memory. Incident response teams should also emphasize credential hygiene and multifactor authentication, as the stolen browser and system credentials form the primary value of these campaigns.
Moreover, the evolution of obfuscation techniques, such as custom function wrappers and layered encoding, highlights a growing arms race between malware developers and cybersecurity solutions. Even advanced EDR solutions triggered only partial alerts, indicating that organizations relying solely on traditional endpoint protections are highly vulnerable. Cyber threat intelligence sharing, timely patching, and user awareness programs remain critical countermeasures.
Fact Checker Results
✅ Remcos RAT has surged in use during September–October 2025.
✅ The malware employs fileless execution and trusted binary injection.
❌ Standard antivirus solutions are sufficient to block this attack (only partial EDR alerts were observed).
Prediction 📊
The Remcos RAT campaign is likely to continue evolving, with attackers refining obfuscation and targeting methods. Organizations can expect:
Increased use of localized phishing campaigns to bypass user awareness.
Expanded deployment of fileless attacks leveraging trusted system binaries.
Greater adoption of encryption and obfuscation layers to bypass next-gen detection.
A surge in credential theft targeting browsers and enterprise applications, making MFA and proactive monitoring essential.
This trend suggests that without adaptive, intelligence-driven cybersecurity strategies, companies remain at high risk of compromise and sensitive data exfiltration.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: cyberpress.org
Extra Source Hub (Possible Sources for article):
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




