Security researchers reported a multi-stage Windows malware campaign dubbed Shadow#Reactor (SHADOW#REACTOR) that uses a VBScript launcher and PowerShell to retrieve fragmented, text-only payloads from remote infrastructure, then reconstructs and executes them to ultimately deploy Remcos RAT. The infection chain relies on user interaction (e.g., phishing/social-engineering lures or compromised web resources) to execute an obfuscated .vbs file via Windows Script Host, after which staged PowerShell downloaders pull encoded payload pieces that are stored as plain text to reduce the likelihood of traditional binary-based detections.
Securonix analysis (as reported in both trade and vendor writeups) describes a modular handoff between stages, including obfuscation layers, base64 decoding patterns, and integrity/size checks to ensure successful reassembly of the final components. The technique emphasizes living-off-the-land execution and flexible staging (allowing attackers to update individual stages independently), with reconstruction activity leveraging legitimate tooling (e.g., MSBuild noted in reporting) before in-memory decoding and retrieval of the final Remcos payload; defenders should treat unusual chains of wscript.exe/cscript.exe spawning PowerShell and subsequent staged text retrieval/reassembly as high-signal behavior for investigation.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers said the activity appears to target enterprises and SMBs in a broad 'spray-and-pray' manner consistent with financially motivated operators or possible initial access broker activity. They also stated there was insufficient evidence to attribute the campaign to a known threat actor.
Technical analysis showed the malware reconstructs payload components from benign-looking text files, decodes .NET assemblies in memory, and uses legitimate Windows tools such as wscript.exe, PowerShell, and MSBuild.exe to reduce on-disk artifacts and evade detection. Securonix also linked the final payload to Remcos RAT through infrastructure tracing and payload signature matching.
Securonix researchers reported a newly identified multi-stage Windows malware campaign dubbed SHADOW#REACTOR. The campaign uses an obfuscated VBS launcher, PowerShell, and text-based payload fragments retrieved from remote infrastructure to ultimately deploy Remcos RAT.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.