How attackers built a RAT on a Windows machine using its own .NET compiler

In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, […]

The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.

This article has been indexed from Heimdal Security Blog

Read the original article: