{"id":5199,"date":"2025-08-03T00:37:48","date_gmt":"2025-08-03T00:37:48","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=5199"},"modified":"2025-08-03T00:37:49","modified_gmt":"2025-08-03T00:37:49","slug":"new-assault-makes-use-of-home-windows-shortcut-information-to-set-up-remcos-backdoor","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=5199","title":{"rendered":"New Assault Makes use of Home windows Shortcut Information to Set up REMCOS Backdoor"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A brand new and misleading multi-stage malware marketing campaign has been recognized by the Lat61 Menace Intelligence crew at safety agency Level Wild. The assault makes use of a intelligent approach involving malicious Home windows Shortcut, or LNK, information, a easy pointer to a program or file, to ship a harmful remote-access trojan (RAT) generally known as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/new-phishing-campaign-dbatloader-drop-remcos-rat\/\" target=\"_blank\" rel=\"noreferrer noopener\">REMCOS<\/a>.<\/p>\n<p>The <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.pointwild.com\/threat-intelligence\/trojan-winlnk-powershell-runner\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">analysis<\/a>, led by Dr. Zulfikar Ramzan, the CTO of Level Wild, and shared with Hackread.com, reveals that the marketing campaign begins with a seemingly innocent shortcut file, presumably hooked up to an e mail, with a filename like \u201c<code>ORDINE-DI-ACQUIST-7263535<\/code>.\u201d<\/p>\n<p>When a consumer clicks on it, the LNK file discreetly runs a PowerShell command within the background. In your data, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/fileless-remcos-rat-attack-antivirus-powershell-scripts\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> is a robust command-line instrument Home windows utilises for job automation; nonetheless, on this assault, it&#8217;s used to obtain\/decode a hidden payload. <\/p>\n<p>This command is designed to obtain and decode a hidden payload with out triggering safety alerts, saving any information, or utilizing macros. The analysis supplies particular file hashes for this LNK file, together with <code>MD5: ae8066bd5a66ce22f6a91bd935d4eee6<\/code>, to assist in detection.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor.png\"><img loading=\"lazy\" decoding=\"async\" width=\"401\" height=\"537\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor.png\" alt=\"\" class=\"wp-image-132892\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor.png 401w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-224x300.png 224w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-380x509.png 380w\" sizes=\"auto, (max-width: 401px) 100vw, 401px\"\/><\/a><figcaption class=\"wp-element-caption\">The LNK File Evaluation (Supply: Level Wild)<\/figcaption><\/figure>\n<\/div>\n<h3 id=\"the-attacks-hidden-layers\" class=\"wp-block-heading\"><strong>The Assault\u2019s Hidden Layers:<\/strong><\/h3>\n<p>This marketing campaign is designed to be stealthy through the use of just a few completely different layers of disguise. After the preliminary PowerShell command runs, it fetches a Base64-encoded payload from a distant server. It is a widespread option to cover malicious code in plain sight, as Base64 is a normal technique for encoding binary knowledge into textual content.<\/p>\n<p>As soon as the payload is downloaded and decoded, it&#8217;s launched as a Program Data File or <code>.PIF<\/code> file, which is a sort of executable usually used for older packages. The attackers disguised this file as <code>CHROME.PIF<\/code> mimicking a professional program. <\/p>\n<p>This ultimate step installs the REMCOS backdoor, giving attackers full management of the compromised system. The malware additionally ensures its persistence on the system by making a log file for its keystroke recording in a brand new Remcos folder beneath the <code>%ProgramData%<\/code> listing.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"753\" height=\"1024\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-1.png\" alt=\"\" class=\"wp-image-132893\" style=\"width:532px;height:auto\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-1.png 753w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-1-221x300.png 221w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/08\/Stealthy-LNK-File-Attack-Delivers-REMCOS-Backdoor-1-380x517.png 380w\" sizes=\"auto, (max-width: 753px) 100vw, 753px\"\/><\/a><figcaption class=\"wp-element-caption\">An infection Workflow (Supply: Level Wild)<\/figcaption><\/figure>\n<\/div>\n<h3 id=\"what-the-remcos-backdoor-can-do\" class=\"wp-block-heading\"><strong>What the REMCOS Backdoor Can Do<\/strong><\/h3>\n<p>As soon as put in, the <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/remcos-malware-campaigns-hit-businesses-and-schools\/\" target=\"_blank\" data-type=\"link\" data-id=\"https:\/\/hackread.com\/remcos-malware-campaigns-hit-businesses-and-schools\/\" rel=\"noreferrer noopener\">REMCOS backdoor<\/a> grants the attackers intensive management over the sufferer\u2019s pc. The menace intelligence report notes that it may carry out a variety of malicious actions, together with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/snake-keylogger-variant-windows-data-telegram-bots\/\" target=\"_blank\" rel=\"noreferrer noopener\">keylogging<\/a> to steal passwords, making a distant shell for direct entry, and getting access to information.<\/p>\n<p>Moreover, the REMCOS backdoor permits the attackers to regulate the pc\u2019s webcam and microphone, enabling them to spy on the consumer. The analysis additionally revealed that the command and management (C2) infrastructure for this particular marketing campaign is hosted in Romania and the US.<\/p>\n<p>This discovering highlights the necessity for warning, as these assaults can originate from anyplace on the planet. Researchers advocate that customers keep cautious with shortcut information from untrusted sources, double-check attachments earlier than opening them, and use up to date <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/10-antivirus-providers-for-pc-mac-android-iphone\/\" target=\"_blank\" data-type=\"post\" data-id=\"51212\" rel=\"noreferrer noopener\">antivirus software program<\/a> with real-time safety.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="Kg9YinU345qzmQdXoqR1"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A brand new and misleading multi-stage malware marketing campaign has been recognized by the Lat61 Menace Intelligence crew at safety agency Level Wild. The assault makes use of a intelligent approach involving malicious Home windows Shortcut, or LNK, information, a easy pointer to a program or file, to ship a harmful remote-access trojan (RAT) generally [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5201,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[717,558,129,1804,557,4444,1059],"class_list":["post-5199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-attack","tag-backdoor","tag-files","tag-install","tag-remcos","tag-shortcut","tag-windows"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5199","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5199"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5199\/revisions"}],"predecessor-version":[{"id":5200,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/5199\/revisions\/5200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/5201"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:22:03 UTC -->