Skip to content

RemCom

RemCom is an open-source remote execution utility for Windows, commonly described as a remote shell or telnet replacement and an open-source replacement for PsExec.

Profile source: Mallory opens in a new tab

RemCom

Family profile

RemCom is an open-source remote execution utility for Windows, commonly described as a remote shell or telnet replacement and an open-source replacement for PsExec. It allows execution of processes on remote Windows systems and is commonly used by attackers for lateral movement and remote service-based execution within compromised networks. The content references detections and telemetry associated with RemCom activity, including Windows service creation events such as RemComSvc and datasets covering Windows Security, Sysmon, and System logs. RemCom has been observed in post-exploitation activity by multiple threat actors. Microsoft reported that MERCURY, now tracked as Mango Sandstorm and assessed with high confidence to be affiliated with Iran’s MOIS, used remote services with RemCom to run encoded PowerShell commands on internal systems after exploiting Log4j 2 vulnerabilities in SysAid Server instances targeting organizations in Israel. APT39 has used RemCom alongside NSSM to execute processes and for lateral movement, particularly in intrusions targeting telecommunications and travel organizations and other entities aligned with Iranian national interests. CrowdStrike reported that FANCY BEAR/APT28 used RemCOM to deploy tools during the 2016 DNC intrusion. Palo Alto Networks reported Stately Taurus (also known as Mustang Panda, BRONZE PRESIDENT, TA416, RedDelta, and Earth Preta) used RemCom for remote execution of exfiltration tools on uncompromised hosts during a long-running cyberespionage campaign against a Southeast Asian government. ESET also reported that IsaacWiper targeted specific machines previously compromised with RemCom, which was described as being used by attackers for lateral movement within compromised networks. High-confidence indicators directly mentioned in the content include the service name RemComSvc and the existence of SHA-256 hashes for RemCom shared by Microsoft in related intrusion reporting, though the specific hash values are not provided in the content.

Reported operators

Threat actors

2 named in public reporting
MuddyWater

Remote services (leveraging RemCom tool) to run encoded PowerShell commands within organizations.

APT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

MITRE ATT&CK

RemCom in ATT&CK

7 distinct techniques

Reporting

Research mentioning RemCom

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Mar 9
Mitre Attack Website

Compromise Accounts, Technique T1586 - Enterprise | MITRE ATT&CK®

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.