Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Obtaining Compensation for Russia’s Ukraine Invasion in US Court

    US DOJ investigates UnitedHealth for alleged Medicare fraud: Report | Business and Economy

    Ukraine’s Zelenskyy sends delegation for Russia talks after Putin no-show | Russia-Ukraine war News

    Facebook X (Twitter) Instagram
    Trending
    • Obtaining Compensation for Russia’s Ukraine Invasion in US Court
    • US DOJ investigates UnitedHealth for alleged Medicare fraud: Report | Business and Economy
    • Ukraine’s Zelenskyy sends delegation for Russia talks after Putin no-show | Russia-Ukraine war News
    • US supreme court live: justices appear divided on federal court powers in birthright citizenship case | Trump administration
    • Giro d’Italia: Mass crash on stage six as Mads Pedersen retains the pink leader’s jersey in Naples
    • George Simion Is Part of Romania’s Very Strange Far Right—and Soon Could Be Its President
    • Alternatives to Microsoft Outlook webmail come under attack in Europe
    • EU: ICJ and other organizations call on EU to respond to escalating crackdown on rule of law
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Stealth RAT uses a PowerShell loader for fileless attacks
    Cyber

    Stealth RAT uses a PowerShell loader for fileless attacks

    mediamillion1000@gmail.comBy [email protected]May 15, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Stealth RAT uses a PowerShell loader for fileless attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    Running shellcode entirely in memory

    Once the obfuscated PowerShell script is executed, it decodes and reconstructs two chunks of base64-encoded data–one is a shellcode loader, the other a PE file (Remcos RAT).

    To run this entirely in memory, the script relies heavily on native Windows API functions, such as VirtualAlloc, Marshal.Copy, and CallWindowProcW, accessed via PowerShell’s ability to interface with unmanaged code.

    Additionally, to stay under the radar, the malware takes a sneakier route: instead of openly listing the Windows tools (APIs) it plans to use, it hunts them down in memory on the fly. This trick, known as “walking the process environment block (PEB),” helps it escape scanners that look for obvious clues, like known file names or function calls.

    “This loader re-frames Remcos as an ephemeral plug-in rather than a resident implant,” Soroko added. “By shifting every stage of the tool-chain into transient memory and dissolving the loader itself once the session ends, the operators make forensic artifacts nearly as disposable as the lure ZIP.”

    Attacks fileless loader PowerShell rat Stealth
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleAnother Reason Trump’s Birthright Citizenship Order is Unlawful
    Next Article Construction sites appear in Gaza ahead of Israeli-US aid plan rejected by UN, images show
    [email protected]
    • Website

    Related Posts

    Alternatives to Microsoft Outlook webmail come under attack in Europe

    May 15, 2025

    Malicious NPM package uses Unicode steganography to evade detection

    May 15, 2025

    Snowflake CISO talks lessons learned from breaches, improv • The Register

    May 15, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Obtaining Compensation for Russia’s Ukraine Invasion in US Court

    US DOJ investigates UnitedHealth for alleged Medicare fraud: Report | Business and Economy

    Ukraine’s Zelenskyy sends delegation for Russia talks after Putin no-show | Russia-Ukraine war News

    US supreme court live: justices appear divided on federal court powers in birthright citizenship case | Trump administration

    Trending Posts

    Obtaining Compensation for Russia’s Ukraine Invasion in US Court

    May 15, 2025

    US DOJ investigates UnitedHealth for alleged Medicare fraud: Report | Business and Economy

    May 15, 2025

    Ukraine’s Zelenskyy sends delegation for Russia talks after Putin no-show | Russia-Ukraine war News

    May 15, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Obtaining Compensation for Russia’s Ukraine Invasion in US Court
    • US DOJ investigates UnitedHealth for alleged Medicare fraud: Report | Business and Economy

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.