❌

Normal view

How attackers built a RAT on a Windows machine using its own .NET compiler

22 June 2026 at 16:37

In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, […]

The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.

Attacker enables RDP, creates admin, erases evidence in ten seconds

22 June 2026 at 10:28

At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them.Β  The intrusion reached 34 endpoints and was over in under ten seconds.Β  Heimdal Extended Threat Protection (XTP) and Ransomware […]

The post Attacker enables RDP, creates admin, erases evidence in ten seconds appeared first on Heimdal Security Blog.

❌