Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Trump hails growing ties with UAE on last leg of Gulf tour | Technology News

    Yamal helps Barcelona seal La Liga title at rivals Espanyol | Football News

    Pregnant US woman declared brain dead is being kept alive under state abortion law | Georgia

    Facebook X (Twitter) Instagram
    Trending
    • Trump hails growing ties with UAE on last leg of Gulf tour | Technology News
    • Yamal helps Barcelona seal La Liga title at rivals Espanyol | Football News
    • Pregnant US woman declared brain dead is being kept alive under state abortion law | Georgia
    • Matty Godden’s late strike fires Charlton past Wycombe into playoff final | League One
    • In Abu Dhabi, Trump makes first visit to a mosque as president : NPR
    • Anthopic’s law firm blames Claude hallucinations for errors • The Register
    • Africa: Persons with Disabilities Push for Inclusive and Accessible Justice Systems
    • Australia news live: Ben Roberts-Smith awaits appeal verdict | Australia news
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Stealth RAT uses a PowerShell loader for fileless attacks
    Cyber

    Stealth RAT uses a PowerShell loader for fileless attacks

    mediamillion1000@gmail.comBy [email protected]May 15, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Stealth RAT uses a PowerShell loader for fileless attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Running shellcode entirely in memory

    Once the obfuscated PowerShell script is executed, it decodes and reconstructs two chunks of base64-encoded data–one is a shellcode loader, the other a PE file (Remcos RAT).

    To run this entirely in memory, the script relies heavily on native Windows API functions, such as VirtualAlloc, Marshal.Copy, and CallWindowProcW, accessed via PowerShell’s ability to interface with unmanaged code.

    Additionally, to stay under the radar, the malware takes a sneakier route: instead of openly listing the Windows tools (APIs) it plans to use, it hunts them down in memory on the fly. This trick, known as “walking the process environment block (PEB),” helps it escape scanners that look for obvious clues, like known file names or function calls.

    “This loader re-frames Remcos as an ephemeral plug-in rather than a resident implant,” Soroko added. “By shifting every stage of the tool-chain into transient memory and dissolving the loader itself once the session ends, the operators make forensic artifacts nearly as disposable as the lure ZIP.”

    Attacks fileless loader PowerShell rat Stealth
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleAnother Reason Trump’s Birthright Citizenship Order is Unlawful
    Next Article Construction sites appear in Gaza ahead of Israeli-US aid plan rejected by UN, images show
    [email protected]
    • Website

    Related Posts

    Anthopic’s law firm blames Claude hallucinations for errors • The Register

    May 15, 2025

    ‘Aggressive, creative’ hackers behind UK breaches now eyeing US retailers

    May 15, 2025

    US officials targeted in voice deepfake attacks since April

    May 15, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Trump hails growing ties with UAE on last leg of Gulf tour | Technology News

    Yamal helps Barcelona seal La Liga title at rivals Espanyol | Football News

    Pregnant US woman declared brain dead is being kept alive under state abortion law | Georgia

    Matty Godden’s late strike fires Charlton past Wycombe into playoff final | League One

    Trending Posts

    Trump hails growing ties with UAE on last leg of Gulf tour | Technology News

    May 15, 2025

    Yamal helps Barcelona seal La Liga title at rivals Espanyol | Football News

    May 15, 2025

    Pregnant US woman declared brain dead is being kept alive under state abortion law | Georgia

    May 15, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Trump hails growing ties with UAE on last leg of Gulf tour | Technology News
    • Yamal helps Barcelona seal La Liga title at rivals Espanyol | Football News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.