TGTGInsighttelegram intelligenceLIVE / telegram public index
← The Hacker News
The Hacker News avatar

TGINSIGHT POST

Post #8194

@thehackernews

The Hacker News

Views9,980Post view count
PostedJan 1301/13/2026, 09:09 AM
Post content

Post content

Researchers uncovered SHADOW#REACTOR, a multi-stage campaign delivering Remcos RAT. It starts with an obfuscated VBS launcher, moves through PowerShell, and rebuilds fragmented text payloads in memory. The defining trait is text-only stagers and LOLBin abuse to reduce detection. 🔗 Read → https://thehackernews.com/2026/01/new-malware-campaign-delivers-remcos.html