{"id":7912,"date":"2025-10-24T10:03:28","date_gmt":"2025-10-24T10:03:28","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/new-fileless-remcos-attacks-bypassing-edrs-malicious-code-into-rmclient\/"},"modified":"2025-10-24T10:03:28","modified_gmt":"2025-10-24T10:03:28","slug":"new-fileless-remcos-attacks-bypassing-edrs-malicious-code-into-rmclient","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/24\/new-fileless-remcos-attacks-bypassing-edrs-malicious-code-into-rmclient\/","title":{"rendered":"New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient"},"content":{"rendered":"<p>    New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Remcos, a commercial remote access tool marketed as legitimate surveillance software, has become the leading infostealer in malware campaigns during the third quarter of 2025, accounting for approximately 11 percent of detected cases.<\/p>\n<p>In a notable shift from traditional deployment methods, threat actors are now weaponizing this remote control and surveillance platform through sophisticated fileless attack chains that successfully evade endpoint detection and response systems.<\/p>\n<p>The malware\u2019s primary motivation centers on <a href=\"https:\/\/cybersecuritynews.com\/credential-theft-risks\/\" target=\"_blank\" rel=\"noreferrer noopener\">credential theft<\/a> through opportunistic targeted attacks, with particular focus on the financial sector, though recent evidence suggests attackers have compromised legitimate websites to host additional malicious payloads supporting the broader operation.<\/p>\n<p>The attack begins deceptively with users receiving emails containing seemingly innocent business attachments. A file named \u201cEFEMMAK TURKEY INQUIRY ORDER NR 09162025.gz\u201d initiates the infection chain.<\/p>\n<p>Once extracted, this archive deploys a batch file into the Windows temporary directory, which subsequently executes a heavily obfuscated PowerShell script employing custom string de-obfuscation functions named \u201cLotusblo\u201d and \u201cGarrots.\u201d<\/p>\n<p>CyberProof analysts <a href=\"https:\/\/www.cyberproof.com\/blog\/fileless-remcos-attacks-on-the-rise\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the PowerShell script initiating hidden processes while configuring web requests to use TLS 1.2 and custom User-Agent strings for legitimate-appearing network traffic.<\/p>\n<p>The script constructs a target file path at C:Users\\AppDataRoamingHereni.Gen and enters a continuous download loop, attempting to retrieve files from a malicious C2 domain every four seconds.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh_awvY5rn9yPUT99xJU5sJlm2JeyM79I2X4bXaazV3vd_JHRhLAnUQAypBzsh9wlt8_2QptDRLC7R4SwK6NWEd0M1fSdactyCykJxZt7bFBl0_UGyEGqdEzP8UORr3yuokbb7oNfCRifvrUd3ljq8Tor707qfqbIJRyMAiQdGuLz4J4aV9nY8xC9GBmNI\/s16000\/Launch%2520of%2520PowerShell%2520script%2520from%2520batch%2520file%2520%28Source%2520-%2520CyberProof%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Launch of PowerShell script from batch file (Source \u2013 CyberProof)<\/figcaption><\/figure>\n<\/div>\n<p>Upon successful download, the script Base64 decodes and GZip decompresses the retrieved payload before executing it through Invoke-Expression, enabling dynamic command execution while leaving no traces on disk.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-process-injection-and-detection-evasion\"><strong>Process Injection and Detection Evasion<\/strong><\/h2>\n<p>The sophisticated technique deployed by attackers involves leveraging msiexec.exe, a legitimate Windows installer executable, to perform process injection into RmClient.exe, a Microsoft-distributed file.<\/p>\n<p>This fileless approach proves effective against traditional <a href=\"https:\/\/cybersecuritynews.com\/best-edr-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">EDR solutions<\/a> because RmClient.exe carries legitimate digital signatures, causing many detection systems to overlook the injected Remcos payload.<\/p>\n<p>Once injected, the malware immediately begins accessing browser credential stores, targeting key4.db, logins.json, and Login Data files containing saved passwords and sensitive authentication information.<\/p>\n<p>Network communications from the compromised RmClient.exe process directed to command-and-control servers at ablelifepurelife.ydns.eu and icebergtbilisi.ge on non-standard ports like 57864 and 50807 reveal the attacker\u2019s infrastructure.<\/p>\n<p>The malware demonstrates <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> through multiple RmClient.exe instances spawning with random parameters stored in the temporary directory, multiplying detection complexity and enabling the threat actor to maintain long-term access for subsequent, more destructive operations.<\/p>\n<p>Organizations must enhance detection capabilities to identify process injection patterns and monitor unusual credential access activities, particularly when involving legitimate system binaries.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-fileless-remcos-attacks-bypassing-edrs\/\">New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-fileless-remcos-attacks-bypassing-edrs\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Fileless Remcos Attacks Bypassing EDRs Malicious Code into RMClient Remcos, a commercial remote access tool marketed as legitimate surveillance software, has become the leading infostealer in malware campaigns during the third quarter of 2025, accounting for approximately 11 percent of detected cases. In a notable shift from traditional deployment methods, threat actors are now [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7912","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7912"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7912"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7912\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7912"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7912"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7912"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}