Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient

Remcos is currently recognized as a leading infostealer in malware campaigns for the third quarter of 2025, representing approximately 11 percent of detected cases. This commercial remote access tool, originally intended for legitimate surveillance, is…

Remcos is currently recognized as a leading infostealer in malware campaigns for the third quarter of 2025, representing approximately 11 percent of detected cases. This commercial remote access tool, originally intended for legitimate surveillance, is now being exploited through advanced fileless attack chains that circumvent endpoint detection and response systems.

The primary objective of this malware is credential theft via targeted attacks, particularly affecting the financial sector. Recent findings indicate that legitimate websites have been compromised to host additional malicious payloads, thereby extending the scope of these operations.

The attack sequence begins with users receiving emails containing seemingly benign business attachments. Upon extraction, an archive file named "EFEMMAK TURKEY INQUIRY ORDER NR 09162025.gz" initiates the infection process. This leads to the deployment of a batch file in the Windows temporary directory, which executes an obfuscated PowerShell script using custom de-obfuscation functions "Lotusblo" and "Garrots."

According to CyberProof analysts, the PowerShell script initiates hidden processes and configures web requests to use TLS 1.2 and custom User-Agent strings for legitimate-looking network traffic. The script constructs a target file path at C:\Users\\AppData\Roaming\Hereni.Gen and enters a continuous download loop, attempting to retrieve files from a malicious command-and-control domain every four seconds.

The primary objective of this malware is credential theft via targeted attacks, particularly affecting the financial sector.
Laura Mitchell · Thehackingpost

Once a download is successful, the script decodes and decompresses the payload using Base64 and GZip, respectively, executing it via Invoke-Expression for dynamic command execution while leaving no disk traces.

Process Injection and Detection Evasion

The attackers employ a sophisticated technique using msiexec.exe, a legitimate Windows installer executable, to inject processes into RmClient.exe, a Microsoft-distributed file. This fileless method effectively bypasses traditional EDR solutions since RmClient.exe carries legitimate digital signatures, causing many detection systems to overlook the injected Remcos payload.

Post-injection, the malware accesses browser credential stores, specifically targeting key4.db, logins.json, and Login Data files containing saved passwords and sensitive authentication information. Network communications from the compromised RmClient.exe process are directed to command-and-control servers at ablelifepurelife.ydns.eu and icebergtbilisi.ge on non-standard ports such as 57864 and 50807, highlighting the attacker's infrastructure.

Advertisement

The malware demonstrates persistence through multiple instances of RmClient.exe spawning with random parameters stored in the temporary directory. This increases detection complexity and allows the threat actor to maintain long-term access for further, potentially more destructive, operations.

Organizations are advised to enhance detection capabilities by identifying process injection patterns and monitoring unusual credential access activities, particularly when they involve legitimate system binaries.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories