A malicious email campaign delivered the MoDi RAT through a multi-stage, largely fileless infection chain that relied on VBScript, PowerShell, Registry-stored payloads, and process injection. The attack began with an email attachment that triggered HTTP 302 redirects to a OneDrive-hosted ZIP archive, then established persistence with a Scheduled Task and stored payload components in the Windows Registry rather than on disk. Sophos reported that some artifacts contained French-language strings and that some of the targeted organizations were French firms.
The intrusion used an unusual evasion technique in which a VBS script opened PowerShell and pasted commands into the console through the clipboard and SendKeys, reducing the visibility of command-line activity to security tools. PowerShell then extracted and reflectively loaded a .NET decoder from the Registry, unpacked an injector and the final payload, and injected the RAT into msbuild.exe without writing the malware to disk. Sophos said AMSI telemetry helped detect and block the attack, while noting that AMSI-based protections are available only on newer Windows platforms including Windows 10 and Windows Server 2016/2019.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Sophos published indicators of compromise related to the investigation on the SophosLabs GitHub, providing technical details tied to the attack chain.
Sophos said it proactively blocked the attack based on its fileless delivery technique and then enhanced existing detections to improve resilience against similar attacks. The company said its products detect components as AMSI/Reflect-D, Troj/VBSInj-D, and AMSI/ModiRat-A.
SophosLabs researchers Fraser Howard and Andrew O’Donnell analyzed an attack chain seen in telemetry that began with a malicious email attachment and ultimately deployed the MoDi RAT remote access Trojan using fileless techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.