Threat intelligence report · AlienVault OTX

Behind the Refund: From GST Phishing to Remcos RAT Through a Multi-Stage .NET Infection Chain

A sophisticated phishing campaign targeting Indian businesses and taxpayers leverages GST-related themes to distribute Remcos RAT through a multi-stage .NET framework. Threat actors impersonate Government of India GST communications using fraudulent refund notifications with convincing ARN references. The attack chain begins with a malicious RAR archive containing a .NET executable that employs bitmap-based payload concealment techniques. Through successive stages including Windows Health Optimizer Plus.dll and perfgurd.dll, the malware deploys Remcos RAT entirely in memory, establishing persistence via PowerShell scripts and registry modifications. Command-and-control infrastructure utilizes dynamic DNS services with randomized subdomains under aofmokighoig.hath.network. The deployed Remcos RAT enables remote command execution, keylogging, credential harvesting, file manipulation, and comprehensive system reconnaissance capabilities, representing a financially motivated cybercrime ope

· unknown severity · unattributed attribution

Evidence and provenance

Original source
AlienVault OTX report ↗
Published
2026-07-17T21:08:32.083000Z
Confidence basis
No actor match
Record ID
a76d7e77b6c1f8018ea2

Affected sectors

government, telecommunications, finance

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.