Skip to main content
← Back to Demos
Malware beginner · 15 min

Remcos-style RAT sample flagged by multi-engine scan

Threat actors published malicious npm packages disguised as PostCSS development tools that install a Windows Remote Access Trojan on developer workstations, giving persistent access, credential theft, and lateral movement into internal development infrastructure. Remote access trojans such as Remcos establish command-and-control sessions that let operators control the machine as if seated in front of it (MITRE T1219). Because RAT binaries are continuously recompiled and repacked, no single antivirus vendor catches every variant. Metascan addresses this by running the sample against 30+ anti-malware engines in parallel, aggregating verdicts into a single risk score so detection gaps in any one engine are covered by the others. This demo uses the EICAR test file, a universally recognized and completely safe signature-checking artifact.

Attack Technique

Remote access trojan

MITRE ATT&CK

T1219 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---