Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection (opens in new tab)
Discover how a new Remcos RAT campaign uses DonutLoader shellcode, AutoIt staging, LOLBins, and in-memory execution to evade detection. G Data analysts reveal the full multi-stage infection chain, from phishing email to process injection and Remcos RAT 7.2.1 Pro deployment.
Read the original article