← Back to Feed
How attackers built a RAT on a Windows machine using its own .NET compiler
June 22, 2026 · Heimdal Security · Severity: MEDIUM
In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so signature antivirus had no known sample to match. The thing that caught it was DNS filtering, […] The post How attackers built a RAT on a Windows machine using its own .NET compiler appeared first on Heimdal Security Blog.
Key Takeaways
- In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file.
- The thing that caught it was DNS filtering, […] The post How attackers built a RAT on a Windows machine using.