From a VHDX File to a Remcos RAT, (Tue, Jun 16th)
2026-06-17T01:23:47Z•6b4fcab09b2300ad15861e3ccf2a34e9269510360eebdde4234721898ff7efca
CSPChromium vulnerabilitiesEdgeEvil MSI BackgroundJavaScriptJune 2026Microsoft Patch TuesdayRATRemcosVHDXWindows auto-mountX-Frame-Optionsimage-steganographymalicious-ZIPmalware-distributionthreat-intel
What happened
Feed includes a report of a malicious ZIP (SHA256 a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) that contains a VHDX which, when auto-mounted on modern Windows, exposes a malicious JavaScript that leads to Remcos RAT distribution. Also highlighted: Microsoft June 2026 Patch Tuesday (204 vulnerabilities, 38 critical, 3 previously disclosed; Edge includes 360 Chromium fixes; six cloud-impacting issues requiring no user action). Other entries cover image-based malware (Evil MSI Background) and an analysis of framing protection headers (X-Frame-Options/CSP frame-ancestors) on 1
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 6b4fcab09b2300ad15861e3ccf2a34e9269510360eebdde4234721898ff7efca
- Enrichment time
- 2026-06-17T01:23:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.