From a VHDX File to a Remcos RAT, (Tue, Jun 16th)

2026-06-16T07:23:48Z873315048a2cc9e8b136d4370abbf378d82b684d18c744160688a364503a445c
Edge/ChromiumJavaScriptJune 2026Microsoft Patch TuesdayRATRemcosVHDXauto-mountmalicious ZIPmalware deliverypatchingthreat intelvulnerabilities

What happened

SANS ISC reports a recent malicious ZIP (SHA256 a0104921...) that contains a VHDX file which, when mounted automatically on modern Windows systems, exposes a malicious JavaScript that leads to deployment of the Remcos RAT. The feed also highlights the June 2026 Microsoft Patch Tuesday: 204 vulnerabilities patched (38 critical), three previously disclosed, six affecting Microsoft cloud services with no user action required, and ~360 Chromium vulnerabilities incorporated into Edge. Relevant operational actions are to block/detect malicious VHDX/ZIP delivery vectors, disable unsafe auto-mounting/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
873315048a2cc9e8b136d4370abbf378d82b684d18c744160688a364503a445c
Enrichment time
2026-06-16T07:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.