Close Menu
TechurzTechurz
    What's Hot

    Databricks hits $188B valuation, extending its run as AI’s favorite second act

    July 17, 2026

    Nuclear startup Valar Atomics in talks to raise new funding at $6B valuation

    July 17, 2026

    Why AMI Labs’ Alexandre LeBrun won’t call his AI ‘AGI’ or ‘superintelligence’

    July 16, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Databricks hits $188B valuation, extending its run as AI’s favorite second act
    • Nuclear startup Valar Atomics in talks to raise new funding at $6B valuation
    • Why AMI Labs’ Alexandre LeBrun won’t call his AI ‘AGI’ or ‘superintelligence’
    • AI-powered travel agency Fora hits unicorn status, raises $60M
    • Sheryl Sandberg leads $10 million investment in AI-powered vehicle inspection service
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Security - Stealth RAT uses a PowerShell loader for fileless attacks
    Security

    Stealth RAT uses a PowerShell loader for fileless attacks

    TechurzBy TechurzMay 15, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Display Showing Stages of Hacking in Progress: Exploiting Vulnerability, Executing and Granted Access.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Running shellcode entirely in memory

    Once the obfuscated PowerShell script is executed, it decodes and reconstructs two chunks of base64-encoded data–one is a shellcode loader, the other a PE file (Remcos RAT).

    To run this entirely in memory, the script relies heavily on native Windows API functions, such as VirtualAlloc, Marshal.Copy, and CallWindowProcW, accessed via PowerShell’s ability to interface with unmanaged code.

    Additionally, to stay under the radar, the malware takes a sneakier route: instead of openly listing the Windows tools (APIs) it plans to use, it hunts them down in memory on the fly. This trick, known as “walking the process environment block (PEB),” helps it escape scanners that look for obvious clues, like known file names or function calls.

    “This loader re-frames Remcos as an ephemeral plug-in rather than a resident implant,” Soroko added. “By shifting every stage of the tool-chain into transient memory and dissolving the loader itself once the session ends, the operators make forensic artifacts nearly as disposable as the lure ZIP.”

    attacks fileless loader PowerShell RAT stealth
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBest Internet Providers in Columbus, Ohio
    Next Article Baby boy was treated with the first personalized gene-editing drug
    Techurz
    • Website

    Related Posts

    Opinion

    Backed by $60M in funding, Oak steps out of stealth to fix the identity mess that AI agents are making worse

    July 15, 2026
    Opinion

    SOND, a sleep tech startup from Bose’s former head of sleep, exits stealth with $7M

    May 27, 2026
    Opinion

    Niv-AI exits stealth to wring more power performance out of GPUs

    March 17, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.