From a VHDX File to a Remcos RAT, (Tue, Jun 16th)
2026-06-16T19:23:44Z•ba7fe7b2c5b8aed6941448884675fbee81438fa7f60c010bfc1b300d2781a4eb
drive-mountingjavascriptmalicious-archivemalware-deliveryratremcossans-iscvhdvhdxvirtual-hard-diskwindows-autorunzip
What happened
SANS ISC reported a malicious ZIP (SHA256 a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094) that contains a VHDX file which, when mounted (automatic on modern Windows), exposes a malicious JavaScript that leads to deployment of the Remcos RAT. This is a file-delivery technique leveraging virtual disk mounting to hide payloads and bypass some detection/inspection mechanisms. Users extracting or mounting archives on Windows may be at risk of remote access trojan infection without additional user interaction.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ba7fe7b2c5b8aed6941448884675fbee81438fa7f60c010bfc1b300d2781a4eb
- Enrichment time
- 2026-06-16T19:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.