· Technical analysis · By IronWort! Team
Dissecting a Multi-Stage Remcos RAT Phishing Campaign: From JavaScript Dropper to Process Hollowing
A full static analysis of a four-stage Remcos RAT infection chain delivered via a phishing email with a JavaScript attachment, steganographic JPEG payload, and process hollowing into RegAsm.exe.