Researchers reported an active phishing campaign targeting users in India with archive attachments disguised as GST debit notes, including files such as GST Debit Note Apr_26.com, to deliver Remcos RAT. The infection chain relies on a multi-stage, largely memory-only loader that uses embedded steganographic payloads, multiple .NET stages, in-memory DLL execution, and process hollowing to evade traditional defenses. Analysis indicates the operation may be part of a loader-as-a-service ecosystem, as related infrastructure has also been linked to payloads including Agent Tesla, RedLine Stealer, Formbook, XWorm, Dark Cloud, Phantom Stealer, MassLogger, and Snake keyloggers.
Once installed, Remcos establishes persistence through Run registry keys and Winlogon/Userinit mechanisms, performs anti-sandbox and anti-VM checks, and attempts UAC bypass via eventviewer.exe. The malware steals browser credentials and cookies, captures user activity, and can record audio and webcam feeds before storing data in logs.dat and exfiltrating it to command-and-control infrastructure including 62.102.148.212:37393. Filenames referencing NEFT, RTGS, IMPS, and GST further indicate the campaign was tailored to Indian financial and business workflows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
JFrog connected the additional npm packages postcss-minify-selector and aes-decode-runner-pro to the same Windows RAT operation. At the time of the report, all three malicious packages were still live on the npm registry.
JFrog identified a supply-chain campaign targeting Windows developers through malicious npm packages masquerading as PostCSS tooling, centered on the typosquatted package postcss-minify-selector-parser. The infection chain used PowerShell, a ZIP payload from nvidiadriver[.]net, and a VBS bootstrapper to install a Windows RAT.
K7 assessed that the same delivery infrastructure was also used to distribute Agent Tesla, Phantom Stealer, Dark Cloud, RedLine Stealer, MassLogger variants, Formbook, XWorm, and Snake keyloggers. The infrastructure reuse and changing payloads suggested a loader-as-a-service operation.
K7 Labs identified a phishing-delivered malware campaign involving the suspicious file "GST Debit Note Apr_26.com," distributed as an archive attachment and themed around Indian financial and tax lures. Analysis showed the campaign used a multi-stage, in-memory steganographic loader to deploy Remcos RAT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcelabs.k7computing.com
Open sourcearyaka.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.