SHADOW#REACTOR Malware Uses PowerShell and MSBuild to Install Remcos RAT

Security researchers have identified a new malware operation, tracked as SHADOW#REACTOR, that uses a carefully layered infection process to install Remcos RAT, a commercially available remote access trojan widely abused by cybercriminals. The campaign relies on a stealthy, multi-step execution…



















