From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

2026-06-17T01:23:47Z6b4fcab09b2300ad15861e3ccf2a34e9269510360eebdde4234721898ff7efca
CSPChromium vulnerabilitiesEdgeEvil MSI BackgroundJavaScriptJune 2026Microsoft Patch TuesdayRATRemcosVHDXWindows auto-mountX-Frame-Optionsimage-steganographymalicious-ZIPmalware-distributionthreat-intel

What happened

Feed includes a report of a malicious ZIP (SHA256 a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) that contains a VHDX which, when auto-mounted on modern Windows, exposes a malicious JavaScript that leads to Remcos RAT distribution. Also highlighted: Microsoft June 2026 Patch Tuesday (204 vulnerabilities, 38 critical, 3 previously disclosed; Edge includes 360 Chromium fixes; six cloud-impacting issues requiring no user action). Other entries cover image-based malware (Evil MSI Background) and an analysis of framing protection headers (X-Frame-Options/CSP frame-ancestors) on 1

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
6b4fcab09b2300ad15861e3ccf2a34e9269510360eebdde4234721898ff7efca
Enrichment time
2026-06-17T01:23:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · From a VHDX File to a Remcos RAT, (Tue, Jun 16th) · Baitaphish