meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9755 Ratings

🗓️ 17 June 2026

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, June 17th, 2026: VHDX to Remocs RAT; Fake Job Offer; OpenBSD Vuln; Copilot M365 Leakage

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, June 17th, 2006 edition of the Science Inundate Storm Center's Stormcast. My name is Johannes Ulrich, recording today from Jacksonville, Florida. And this episode is brought you by the sands.edu credit certificate program in cloud security.

0:24.1

One thing we really like is when readers actually send us malware samples.

0:29.9

We love malware samples on our website.

0:32.3

You can actually download malware samples via our contact forum.

0:36.4

And Xavier took a look at a sample we received

0:40.0

yesterday from a user. First of all, this sample arrives as a VHDX file. These are disk images,

0:47.8

so once you download the file, it in Windows will actually typically automatically mount itself and with that

0:56.4

start off some JavaScript. Now the JavaScript has not only obfuscated also the way it starts

1:04.0

the PowerShell strip then that will actually, well, load additional malware, is interesting in

1:10.2

that it goes via WMI. WMI, typically more used

1:13.8

sort of for remote access to other systems. But here using the chain JavaScript,

1:19.8

WMI, and then PowerShell, well, makes this less suspicious to some endpoint protection systems

1:26.0

than going JavaScript to PowerShell directly.

1:30.2

So that's what the attacker is trying to accomplish here. They're trying to further obfuscate,

1:35.3

not just the Malware itself, but also the behavior that is being exhibited by the Malware.

1:40.9

And that, of course, goes straight against some of these more modern endpoint protection

1:46.0

systems. There are a couple more stages, but in the end, the victim ends up with Remco's

1:52.1

rat, good old remote access tool, have talked about this for years, and a virus, end point

1:58.1

protection still appears to be having a hard time with it.

2:09.5

But anyway, the behavior here is quite telling and definitely something that you want to check your endpoint protection systems for to check if they are actually alerting on some of these more obfuscated execution paths.

2:17.4

And there's hardly been a podcast where I haven't talked about some kind of supply chain. more obfuscated execution paths.

2:21.8

And there's hardly been a podcast where I haven't talked about some kind of supply chain issue today a little bit of different perspective of it, and that's, well, more the defensive

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.