Cybersecurity researchers have revealed details of a new campaign dubbed SHADOW#REACTOR, which uses a flexible multi-layered attack chain to distribute the Remcos RAT and establish persistent, covert remote access.

“ The infection chain follows a tightly orchestrated execution path: an obfuscated VBS launcher, executed via wscript.exe, calls a PowerShell downloader, which retrieves fragmented, text-based payloads from a remote server ,” said Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee.
See also: ValleyRAT_S2 attacks organizations to install malware
“These fragments are reassembled into encoded loaders, decoded in memory by a .NET Reactor–protected assembly, and used to retrieve and apply a remote Remcos configuration. The final stage leverages MSBuild.exe as a 'living-off-the-land' binary (LOLBin) to complete execution, after which the Remcos RAT backdoor is fully deployed and takes control of the compromised system.“.
The activity is assessed as broad and opportunistic, primarily targeting enterprise and small and medium-sized business environments. The tools and techniques align with typical initial access brokers, who gain access to targeted environments and sell them to other actors for financial gain. There is no evidence linking the campaign to a known threat actor.

What sets this new Remcos RAT campaign apart – Chain of infection
The most unusual aspect of the campaign is the reliance on intermediate text-only stagers, combined with the use of PowerShell (for in-memory recompilation) and a .NET Reactor–protected reflective loader for unpacking subsequent phases of the attack. All of these processes are aimed at making detection and analysis difficult.
The infection sequence begins with the retrieval and execution of an obfuscated Visual Basic Script (“win64.vbs”) that is likely triggered by user interaction, such as clicking on a link delivered via decoys. The script, executed using “wscript.exe”, acts as a lightweight launcher for a Base64-encoded PowerShell payload.
See also: Guloader: New campaign exploits fear in the workplace
The PowerShell script then uses System.Net.WebClient to communicate with the same server used to retrieve the VBS file. It also drops a text-based payload named “qpwoe64.txt” (or “qpwoe32.txt” for 32-bit systems) into the machine’s %TEMP% directory.
“The script then enters a loop where it validates the existence and size of the file,” Securonix explained. “If the file is missing or below the specified length threshold (minLength), the stager pauses execution and reloads the content. If the threshold is not reached within the specified timeout window (maxWait), execution continues without terminating, preventing the chain from failing.”
“This mechanism ensures that incomplete or corrupted payload fragments do not immediately interrupt execution, reinforcing the self-healing design of the campaign.”

If the text file meets the relevant criteria, it proceeds to build a second PowerShell script (“jdywa.ps1”) in the %TEMP% directory, which calls a .NET Reactor Loader responsible for establishing persistence, retrieving the next-stage malware , and incorporating various anti-debugging and anti-VM checks.
The loader eventually launches the Remcos RAT malware on the compromised system using a legitimate Microsoft Windows process, “MSBuild.exe.” Also, during the attack, wrapper scripts to restart the execution of “win64.vbs” using “wscript.exe.”
See also: MuddyWater uses malicious Word documents to distribute RustyWater
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“Overall, these behaviors indicate an actively maintained and modular loader framework, designed to maintain the Remcos payload,” the researchers noted. “The combination of text-only intermediates, in-memory .NET Reactor loaders, and LOLBin abuse reflects a deliberate strategy that evades antivirus signatures, sandboxes, and rapid analysis by analysts.”
