In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, […]
The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.
