From phishing attachment to in-memory stealer: dissecting a Donut-wrapped Remington payload
A phishing attachment led to an obfuscated BAT, a reconstructed PowerShell loader, and a Donut-wrapped .NET stealer running inside explorer.exe. Telegram exfiltration was attempted — and failed.
