Reloaded in a modern Remcos RAT Infection

June 1, 2026, 9:51 a.m.

Description

Analysts discovered a new Remcos RAT infection chain starting with a batch file executing encoded commands that creates hidden directories and retrieves encrypted payloads. Unlike earlier campaigns relying on PowerShell-hosted .NET loaders, this variant incorporates DonutLoader shellcode and AutoIt-based staging for in-memory payload delivery. The infection begins with a phishing email containing a malicious batch file named Bestellung.CMD. The chain abuses legitimate Windows utilities including cscript.exe and SyncAppvPublishingServer.vbs to execute Base64-encoded payloads. Additional components are downloaded from cloud storage, including 7Zip tools and password-protected archives containing obfuscated JScript. The final payload consists of DonutLoader shellcode that injects Remcos RAT version 7.2.1 Pro into colorcpl.exe, enabling remote control, credential harvesting, keystroke logging, and additional payload deployment.

Date

  • Created: May 30, 2026, 12:22 a.m.
  • Published: May 30, 2026, 12:22 a.m.
  • Modified: June 1, 2026, 9:51 a.m.

Indicators

  • 14a0d7978872a2739ac31ef42539e8c708af6afccc5eb74f22fe2b676bfa2df7
  • 5b3089eefab0e043af8894de86022bdc6df2f42f7098dbd530f42c0ec861d5d8
  • b9da295c34accf3632c2c4b6d9e3c74791b4514d27814f79e9bcb77ce168a347
  • 48bd36c3b8d6a3bf5db4e7b0bbc1692e8cb900475dc7ae16e9f1fa7ba97c8adf

Attack Patterns