New SHADOW#REACTOR Malware Campaign Uses Remcos RAT in Multi-Stage Attack
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The SHADOW#REACTOR campaign, disclosed on January 13, 2026, employs a sophisticated multi-stage attack chain to deliver the Remcos RAT, a commercially available remote administration tool. Cybersecurity researchers from Securonix detailed how the attack begins with an obfuscated Visual Basic Script (“win64.vbs”) that is likely triggered by user interaction, such as clicking a malicious link. This script uses wscript.exe to launch a PowerShell downloader that retrieves fragmented payloads from a remote server.
The PowerShell script communicates with the same server to drop a text-based payload named “qpwoe64.txt” in the machine’s %TEMP% directory. If the file meets certain criteria, it constructs a secondary PowerShell script, “jdywa.ps1,” which invokes a .NET Reactor Loader to establish persistence and retrieve the next stage of malware. The loader ultimately launches the Remcos RAT using the legitimate Microsoft Windows process, “MSBuild.exe.” This campaign targets enterprise and small-to-medium business environments, reflecting a broader trend of opportunistic attacks.
Implications for Cybersecurity
The reliance on text-only intermediates and the use of in-memory loaders are designed to evade detection by antivirus software and complicate analysis. This indicates a shift towards more sophisticated tactics among threat actors, making it crucial for organizations to enhance their security measures. Users should be cautious of unsolicited links and verify the legitimacy of scripts before execution.
Organizations should also consider implementing robust monitoring systems to detect unusual behavior indicative of such attacks. Regular training on recognizing phishing attempts and maintaining updated security protocols can help mitigate risks associated with these types of malware campaigns.
- Remcos RAT: A remote administration tool used in the SHADOW#REACTOR campaign to gain control over compromised systems.
- PowerShell: A scripting language used in the attack to download and execute malicious payloads.
- MSBuild.exe: A legitimate Microsoft Windows process exploited to launch the Remcos RAT.
- VBS: Visual Basic Script, which initiates the infection chain in this malware campaign.
- Text-based payloads: Fragments used to complicate detection and analysis efforts during the attack.
Key Takeaways
- Be cautious of clicking on links in unsolicited emails or messages, as they may lead to malware infections.
- Regularly update antivirus and security software to improve detection of sophisticated malware.
- Implement user training programs to recognize phishing attempts and suspicious scripts.
- Monitor network activity for unusual behavior that may indicate a malware infection.
- Establish robust backup procedures to recover data in case of a successful malware attack.
Key Terms & Concepts
- Remcos RAT: In this article, Remcos RAT refers to a remote administration tool used by attackers to gain control over compromised systems.
- PowerShell: PowerShell is a scripting language used in the attack to download and execute malicious payloads.
- MSBuild.exe: MSBuild.exe is a legitimate Microsoft Windows process exploited to launch the Remcos RAT.
- VBS: VBS stands for Visual Basic Script, which initiates the infection chain in this malware campaign.
- Text-based payloads: Text-based payloads are fragments used to complicate detection and analysis efforts during the attack.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.