Skip to content

Remcos

Remcos RAT is a commercial Windows remote-access trojan sold by Breaking Security that has been repeatedly abused in criminal malware campaigns.

Profile source: Mallory opens in a new tab

Remcos

Family profile

Remcos RAT is a commercial Windows remote-access trojan sold by Breaking Security that has been repeatedly abused in criminal malware campaigns. It provides remote control of compromised hosts and supports automated screen capture, Windows Registry modification, Registry Run-key persistence, and concealed window execution. It has been distributed through malspam, including business-themed requests, orders, receipts, payments, and document lures. APT-C-36 (Blind Eagle) has used Remcos RAT among its commodity remote-access tools in campaigns targeting organizations in Colombia and elsewhere in South America. Remcos RAT has also been delivered by the .NET-based GraftLoader component in Operation LoremDrop, where encrypted payloads were loaded in memory and executed through process hollowing. The malware is associated with Windows environments.

Capabilities

  • Defense Evasion
  • Persistence
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 22, 2026
Last activity
Aug 29, 2026
Feed role
C2 / Distribution
Host form
203 IP / 289 hostnames

Leading locations

  • US157
  • NL35
  • CN27
  • DE27
  • HK13
  • TR13
  • LU10
  • RU9
  • SG9
  • SE8
  • FR7
  • PL7

Leading providers

  • Cloudflare, Inc.47
  • HostPapa29
  • Wowrack.com15
  • Fiba Cloud Operation Company, LLC13
  • Google LLC11
  • Ghosty Networks LLC10

Infrastructure traits

  • Hosting 355
  • Anycast 49
  • Vpn 1

Samples

Recent associated samples

Reported operators

Threat actors

63 named in public reporting
SHADOW-WATER-84

“Campaign 2 payload is Remcos, the commercial remote administration tool sold by Breaking Security.”

APT-C-36

“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Remcos RAT ...”

Sable Squirrel

к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT

UAC-0050

Later, on November 12th, 2024, another spam campaign was launched ... Inside this RAR archive could be found a 32-bit executable Remcos payload that would communicate with its C2 on IP ‘111.90.140[.]65:2404’ and botnet ID “hstnw”.

Tor2Mine

The campaign included the use of a variant of AZORult, an information-stealing malware; as well as the RAT Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.

DDGroup

To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: Remcos RAT

Elfin Group

Remcos communicates over non-HTTP/S channels/ports on custom protocols. The bot can be configured to communicate in plain text... however, in most cases, the communication is encrypted using the RC4 algorithm with a key present in the configuration.

Gorgon Group

Remcos communicates over non-HTTP/S channels/ports on custom protocols. The bot can be configured to communicate in plain text... however, in most cases, the communication is encrypted using the RC4 algorithm with a key present in the configuration.

UAC-0184

Flow: #Phishing > #MaliciousDocs > #RAT (#Remcos) > #Persistence > #PrivilegeEsc > #C2 > #Exfiltration

FIN7

In this two-part blog we are going to address two tools used by this group — JSS Loader and Remcos.

Vendetta

In addition to the nature of the backdoor virus, ReZer0 also carries known remote control Trojans such as NanoCore and Remcos in the resources.

Bitter

PlugX, ShadowPad and Cobalt Strike point to China-nexus operators; a Remcos cluster was tied to a suspected India-nexus actor Recorded Future tracks as TAG-179, overlapping with the group others call Bitter.

TAG-179

PlugX, ShadowPad and Cobalt Strike point to China-nexus operators; a Remcos cluster was tied to a suspected India-nexus actor Recorded Future tracks as TAG-179, overlapping with the group others call Bitter.

UAT-11795

Depending on operator objectives, Starland RAT can deploy CastleStealer, Remcos RAT, or the previously undocumented WLDR framework.

Mysterious Elephant

The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.

SideWinder

Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.

Confucius

Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.

TA558

[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)

MB-0005

The modular HijackLoader bundle decodes Remcos Agent 7.1.0 Pro, configured to communicate with the same server that delivered the initial PowerShell stages and secondary archive: 144.31.236.240:27018

SmartApeSG

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

TA2722

TA2722 distributes Remcos and NanoCore remote access trojans (RATs). Remcos and NanoCore are typically used for information gathering, data theft operations, monitoring and control of compromised computers.

SilverTerrier

Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.

BoredFluff

Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.

BlackToad

Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.

Scarlet Goldfinch

In a shift from Scarlet Goldfinch’s usual payload, the malicious DLL sideloads the Remcos remote access tool, replacing the expected NetSupport Manager.

Gamaredon Group

Remcos has a command to hide itself through injecting into another process.

APT33

Remcos (Backdoor.Remvio): A commodity remote administration tool (RAT) that can be used to steal information from an infected computer.

BO Team

The attackers typically use targeted phishing emails with malicious files disguised as legitimate documents to gain initial access, and deploy backdoors such as BrockenDoor, as well as other malware including Remcos and DarkGate.

ZPHP

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

HANEYMANEY

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

Prince of Persia

The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...

RATicate

"Some of the payloads identified for campaign 2... included... RAT Remcos"

BRONZE BUTLER

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Blue Mockingbird

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Dark Caracal

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

WIZARD SPIDER

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Group5

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

TA505

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Kimsuky

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

APT32

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

MoustachedBouncer

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Medusa Group

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

INDRIK SPIDER

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

APT41

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Lotus Blossom

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

OilRig

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Dragonfly

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

APT39

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

FIN8

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

GOLD SOUTHFIELD

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Winter Vivern

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Turla

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Silence

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Volt Typhoon

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Ember Bear

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

BlackByte

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Threat Group-3390

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Mustang Panda

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Magic Hound

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Patchwork

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

MuddyWater

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

APT42

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

APT38

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Exploited software

Vulnerabilities linked to Remcos

8 CVEs

MITRE ATT&CK

Remcos in ATT&CK

100 distinct techniques

Techniques

100 techniques
T1123 Audio Capture T1113 Screen Capture T1071.001 Web Protocols T1115 Clipboard Data T1219 Remote Access Tools T1056.001 Keylogging T1566.001 Spearphishing Attachment T1566 Phishing T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1059.003 Windows Command Shell T1059.005 Visual Basic T1027.003 Steganography T1584 Compromise Infrastructure T1553.002 Code Signing T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1112 Modify Registry T1588.001 Malware T1548.002 Bypass User Account Control T1083 File and Directory Discovery T1547.001 Registry Run Keys / Startup Folder T1564.003 Hidden Window T1583.001 Domains T1125 Video Capture T1056 Input Capture T1614 System Location Discovery T1204.002 Malicious File T1090 Proxy T1129 Shared Modules T1539 Steal Web Session Cookie T1055 Process Injection T1204.001 Malicious Link T1140 Deobfuscate/Decode Files or Information T1036 Masquerading T1571 Non-Standard Port T1497.001 System Checks T1027.002 Software Packing T1562.001 Disable or Modify Tools T1027.013 Encrypted/Encoded File T1137 Office Application Startup T1003 OS Credential Dumping T1055.012 Process Hollowing T1566.002 Spearphishing Link T1548 Abuse Elevation Control Mechanism T1059.001 PowerShell T1082 System Information Discovery T1053.005 Scheduled Task T1041 Exfiltration Over C2 Channel T1620 Reflective Code Loading T1204 User Execution T1218.009 Regsvcs/Regasm T1518 Software Discovery T1070.004 File Deletion T1573 Encrypted Channel T1068 Exploitation for Privilege Escalation T1057 Process Discovery T1218.010 Regsvr32 T1197 BITS Jobs T1568 Dynamic Resolution T1010 Application Window Discovery T1078 Valid Accounts T1005 Data from Local System T1203 Exploitation for Client Execution T1547.009 Shortcut Modification T1543 Create or Modify System Process T1560 Archive Collected Data T1095 Non-Application Layer Protocol T1555 Credentials from Password Stores T1574.001 DLL T1218.005 Mshta T1529 System Shutdown/Reboot T1218.003 CMSTP T1568.003 DNS Calculation T1566.003 Spearphishing via Service T1489 Service Stop T1106 Native API T1222 File and Directory Permissions Modification T1555.003 Credentials from Web Browsers T1114 Email Collection T1567.002 Exfiltration to Cloud Storage T1567 Exfiltration Over Web Service T1218 System Binary Proxy Execution T1070 Indicator Removal T1562 Impair Defenses T1547 Boot or Logon Autostart Execution T1020 Automated Exfiltration T1047 Windows Management Instrumentation T1053 Scheduled Task/Job T1190 Exploit Public-Facing Application T1127 Trusted Developer Utilities Proxy Execution T1217 Browser Information Discovery T1046 Network Service Discovery T1016 System Network Configuration Discovery T1055.002 Portable Executable Injection T1027.007 Dynamic API Resolution T1587.001 Malware T1059.010 AutoHotKey & AutoIT T1564.001 Hidden Files and Directories T1568.001 Fast Flux DNS

Reporting

Research mentioning Remcos

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 30
Splunk Research

Detection: Windows Suspicious Child Process of Consent.EXE | Splunk Security Content

Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 27
Netresec

PureLogs, PureRAT and misleading zgRAT

Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.

Jul 26
Securonix

Securonix Threat Research Security Advisory: New RE#TURGENCE Attack Campaign: Turkish Hackers Target MSSQL Servers to Deliver Domain-Wide MIMIC Ransomware - Securonix

Threat actors have been targeting poorly secured, internet-exposed Microsoft SQL Server instances to deliver Mimic and Trigona ransomware, using brute-force or weak credentials and, in some cases, xp_cmdshell for command execution. Researchers reported that one actor used the SQL Server Bulk Copy Program (BCP) utility to rebuild malware from database contents onto disk, while other intrusions relied on PowerShell download cradles, mounted SMB shares, and remote access tools including AnyDesk. In multiple cases, the attackers established persistence, created administrator accounts, enabled credential theft opportunities such as the WDigest\UseLogonCredential registry setting, and deployed tooling including Mimikatz, PsExec, Advanced Port Scanner, Defender Control, and SDelete.

Jul 23
Security Online Info

GST Phishing Campaign Distributes Remcos RAT Malware

Attackers used spoofed Government of India GST refund emails to target Indian businesses and taxpayers, luring recipients into opening a malicious RAR attachment that launched a multi-stage .NET infection chain and ultimately deployed Remcos RAT. Seqrite reported that the initial executable unpacked successive in-memory loaders hidden in bitmap resources and DLL stages, including Windows Health Optimizer Plus.dll and perfgurd.dll, while using reflection, XOR-based decryption, and architecture-aware method dispatch to evade analysis and execute the final payload. The campaign established persistence by copying the executable and launching a PowerShell script through a Run registry key, and it attempted privilege escalation via cmstp.exe. The final Remcos RAT payload enabled remote access, credential theft, surveillance, and delivery of additional malware. Infrastructure tied to the operation included dynamic DNS domains under hath.network and synology.me, with command-and-control activity resolving to 185.242.4.122 on hosting associated with M247 Europe SRL; researchers assessed the activity as likely financially motivated cybercrime but did not attribute it to a known threat actor.

Jul 22
Security Online Info

Starland RAT: Russian Actor UAT-11795 Hits Crypto Users

Cisco Talos reported that Russian-speaking threat actor UAT-11795 has run a financially motivated malware campaign since at least June 2025, primarily targeting users in the United States and also affecting victims in Germany, Romania, and Venezuela. The operation uses ClickFix-style lures, weaponized HTA files, and trojanized NSIS installers masquerading as legitimate software such as Zoom and Webex to deliver a Python-based backdoor dubbed Starland RAT. Talos said the malware establishes persistence, performs sandbox checks, and collects extensive host, browser, Active Directory, credential, and cryptocurrency wallet data. Researchers said Starland RAT also supports remote command execution, screenshot capture, shellcode injection, and delivery of follow-on payloads including CastleStealer and Remcos RAT. Talos additionally identified a bespoke in-memory PowerShell implant called WLDR, which uses encrypted command-and-control tied to a victim hardware identifier for reconnaissance and modular tasking. The campaign relies on distributed staging and C2 infrastructure, including Telegram bots for execution alerts and victim profiling, and a Polygon smart contract that provides a fallback mechanism for resolving C2 domains when primary infrastructure is disrupted.

Jul 22
Security Online Info

TTF Trap: Fake Font Files Hide a Stealthy Lua Loader

A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.