home.social

#remotecommandexecution — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remotecommandexecution, aggregated by home.social.

  1. Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

    A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t...

    Pulse ID: 6a5a0f86e175ec219dfa17b2
    Pulse Link: otx.alienvault.com/pulse/6a5a0
    Pulse Author: AlienVault
    Created: 2026-07-17 11:18:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberCrime #CyberSecurity #DNS #Government #India #InfoSec #Malware #NET #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Remcos #RemcosRAT #RemoteCommandExecution #Windows #bot #AlienVault

  2. Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

    A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime operation specifically t...

    Pulse ID: 6a5a0f86e175ec219dfa17b2
    Pulse Link: otx.alienvault.com/pulse/6a5a0
    Pulse Author: AlienVault
    Created: 2026-07-17 11:18:30

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CredentialHarvesting #CyberCrime #CyberSecurity #DNS #Government #India #InfoSec #Malware #NET #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Remcos #RemcosRAT #RemoteCommandExecution #Windows #bot #AlienVault

  3. From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

    A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise.

    Pulse ID: 6a4d09e0fbf878666b3d5afd
    Pulse Link: otx.alienvault.com/pulse/6a4d0
    Pulse Author: AlienVault
    Created: 2026-07-07 14:14:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Endpoint #ICS #InfoSec #LUA #Nim #OTX #OpenThreatExchange #Phishing #RAT #RCE #RemoteAccessTrojan #RemoteCommandExecution #SpearPhishing #Trojan #VNC #Windows #bot #AlienVault

  4. From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

    A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise.

    Pulse ID: 6a4d09e0fbf878666b3d5afd
    Pulse Link: otx.alienvault.com/pulse/6a4d0
    Pulse Author: AlienVault
    Created: 2026-07-07 14:14:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Endpoint #ICS #InfoSec #LUA #Nim #OTX #OpenThreatExchange #Phishing #RAT #RCE #RemoteAccessTrojan #RemoteCommandExecution #SpearPhishing #Trojan #VNC #Windows #bot #AlienVault

  5. From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

    A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise.

    Pulse ID: 6a4d09e0fbf878666b3d5afd
    Pulse Link: otx.alienvault.com/pulse/6a4d0
    Pulse Author: AlienVault
    Created: 2026-07-07 14:14:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Endpoint #ICS #InfoSec #LUA #Nim #OTX #OpenThreatExchange #Phishing #RAT #RCE #RemoteAccessTrojan #RemoteCommandExecution #SpearPhishing #Trojan #VNC #Windows #bot #AlienVault

  6. From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

    A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise.

    Pulse ID: 6a4d09e0fbf878666b3d5afd
    Pulse Link: otx.alienvault.com/pulse/6a4d0
    Pulse Author: AlienVault
    Created: 2026-07-07 14:14:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Endpoint #ICS #InfoSec #LUA #Nim #OTX #OpenThreatExchange #Phishing #RAT #RCE #RemoteAccessTrojan #RemoteCommandExecution #SpearPhishing #Trojan #VNC #Windows #bot #AlienVault

  7. From Phishing to Persistence: A CrySome RAT Infection Chain Analysis

    A sophisticated multi-stage infection chain was analyzed following successful containment by MDR SOC operations. Initial access occurred through spear-phishing using a logistics rate confirmation lure, delivering CrySome remote access trojan via multiple stages. The attack chain leveraged living-off-the-land techniques, ICMLuaUtil COM interface for UAC bypass, and in-memory AMSI patching. WinDefCtl, an open-source Defender disruption tool, was deployed to weaken endpoint protections before the final payload. CrySome RAT established persistence through scheduled tasks and provided operators with capabilities including hidden VNC, remote command execution, system reconnaissance, and credential theft targeting Chromium-based browsers. The campaign demonstrated modern threat actors' reliance on publicly available tooling combined with legitimate Windows processes to minimize detection while achieving comprehensive system compromise.

    Pulse ID: 6a4d09e0fbf878666b3d5afd
    Pulse Link: otx.alienvault.com/pulse/6a4d0
    Pulse Author: AlienVault
    Created: 2026-07-07 14:14:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #Endpoint #ICS #InfoSec #LUA #Nim #OTX #OpenThreatExchange #Phishing #RAT #RCE #RemoteAccessTrojan #RemoteCommandExecution #SpearPhishing #Trojan #VNC #Windows #bot #AlienVault

  8. The Crown Prince, Nezha

    Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability.

    Pulse ID: 6a4828eab61bec7567ac88b1
    Pulse Link: otx.alienvault.com/pulse/6a482
    Pulse Author: AlienVault
    Created: 2026-07-03 21:26:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #China #CyberSecurity #HongKong #InfoSec #Japan #Korea #Mac #OTX #OpenThreatExchange #PHP #RAT #RCE #RemoteCommandExecution #SouthKorea #Troll #Word #bot #phpMyAdmin #AlienVault

  9. The Crown Prince, Nezha

    Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability.

    Pulse ID: 6a4828eab61bec7567ac88b1
    Pulse Link: otx.alienvault.com/pulse/6a482
    Pulse Author: AlienVault
    Created: 2026-07-03 21:26:02

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #China #CyberSecurity #HongKong #InfoSec #Japan #Korea #Mac #OTX #OpenThreatExchange #PHP #RAT #RCE #RemoteCommandExecution #SouthKorea #Troll #Word #bot #phpMyAdmin #AlienVault