Last seven days
- First activity
- Aug 22, 2026
- Last activity
- Aug 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 203 IP / 289 hostnames
Remcos RAT is a commercial Windows remote-access trojan sold by Breaking Security that has been repeatedly abused in criminal malware campaigns.
Profile source: Mallory opens in a new tabRemcos
Remcos RAT is a commercial Windows remote-access trojan sold by Breaking Security that has been repeatedly abused in criminal malware campaigns. It provides remote control of compromised hosts and supports automated screen capture, Windows Registry modification, Registry Run-key persistence, and concealed window execution. It has been distributed through malspam, including business-themed requests, orders, receipts, payments, and document lures. APT-C-36 (Blind Eagle) has used Remcos RAT among its commodity remote-access tools in campaigns targeting organizations in Colombia and elsewhere in South America. Remcos RAT has also been delivered by the .NET-based GraftLoader component in Operation LoremDrop, where encrypted payloads were loaded in memory and executed through process hollowing. The malware is associated with Windows environments.
C2 tracking
Derp observations, rolling seven-day window
Samples
329aa4b71b39b71b38c2b5140af2f7436242f1c1eddd80a419325e2bf7ee5665 427727be19870488d1c57821e05448c09f72354cc271f4a91479301d7bfad865 957158c4fb4ee442da50e7aa5899b6f663f85b793bdbd5fcfef5cedd079bfec1 d05d15fdc8479e6c5bdd3de8acc9a491ce2103fdf9b208ec6588c6af46f783f1 ec9da409fed562ffeafd6422ff22e4b21a643a2b627bb36225ed8921fb396b58 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef cdbaf394a5131c73749596457d10837466f437b245986fadf409290ddaf18629 Reported operators
“Campaign 2 payload is Remcos, the commercial remote administration tool sold by Breaking Security.”
“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Remcos RAT ...”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Later, on November 12th, 2024, another spam campaign was launched ... Inside this RAR archive could be found a 32-bit executable Remcos payload that would communicate with its C2 on IP ‘111.90.140[.]65:2404’ and botnet ID “hstnw”.
The campaign included the use of a variant of AZORult, an information-stealing malware; as well as the RAT Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.
To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: Remcos RAT
Remcos communicates over non-HTTP/S channels/ports on custom protocols. The bot can be configured to communicate in plain text... however, in most cases, the communication is encrypted using the RC4 algorithm with a key present in the configuration.
Remcos communicates over non-HTTP/S channels/ports on custom protocols. The bot can be configured to communicate in plain text... however, in most cases, the communication is encrypted using the RC4 algorithm with a key present in the configuration.
Flow: #Phishing > #MaliciousDocs > #RAT (#Remcos) > #Persistence > #PrivilegeEsc > #C2 > #Exfiltration
In this two-part blog we are going to address two tools used by this group — JSS Loader and Remcos.
In addition to the nature of the backdoor virus, ReZer0 also carries known remote control Trojans such as NanoCore and Remcos in the resources.
PlugX, ShadowPad and Cobalt Strike point to China-nexus operators; a Remcos cluster was tied to a suspected India-nexus actor Recorded Future tracks as TAG-179, overlapping with the group others call Bitter.
PlugX, ShadowPad and Cobalt Strike point to China-nexus operators; a Remcos cluster was tied to a suspected India-nexus actor Recorded Future tracks as TAG-179, overlapping with the group others call Bitter.
Depending on operator objectives, Starland RAT can deploy CastleStealer, Remcos RAT, or the previously undocumented WLDR framework.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The modular HijackLoader bundle decodes Remcos Agent 7.1.0 Pro, configured to communicate with the same server that delivered the initial PowerShell stages and secondary archive: 144.31.236.240:27018
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
TA2722 distributes Remcos and NanoCore remote access trojans (RATs). Remcos and NanoCore are typically used for information gathering, data theft operations, monitoring and control of compromised computers.
Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.
Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.
Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.
In a shift from Scarlet Goldfinch’s usual payload, the malicious DLL sideloads the Remcos remote access tool, replacing the expected NetSupport Manager.
Remcos has a command to hide itself through injecting into another process.
Remcos (Backdoor.Remvio): A commodity remote administration tool (RAT) that can be used to steal information from an infected computer.
The attackers typically use targeted phishing emails with malicious files disguised as legitimate documents to gain initial access, and deploy backdoors such as BrockenDoor, as well as other malware including Remcos and DarkGate.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
"Some of the payloads identified for campaign 2... included... RAT Remcos"
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
Exploited software
MITRE ATT&CK
Reporting
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Splunk published a Windows endpoint analytic that detects suspicious child processes launched by consent.exe, a behavior strongly associated with User Account Control (UAC) bypass and privilege escalation. Because consent.exe normally displays the UAC elevation prompt rather than spawning executables, the detection treats such process creation as anomalous, excluding WerFault.exe as a known crash-related exception. The analytic maps to MITRE ATT&CK techniques T1548.002, T1068, and T1059, and is designed for telemetry from Sysmon, Windows Security Event ID 4688, and CrowdStrike ProcessRollup2 data normalized into Splunk's Endpoint data model. The release aligns with MITRE ATT&CK documentation showing UAC bypass remains a widely used post-compromise technique across ransomware operators, commodity malware, and state-linked intrusion groups. ATT&CK lists methods including COM abuse through CMSTPLUA, scheduled task abuse such as SilentCleanup, registry hijacks involving ms-settings and mscfile, and abuse of trusted Windows binaries including fodhelper.exe, eventvwr.exe, and sdclt.exe. Splunk also published supporting attack simulation data for suspicious child processes of consent.exe, giving defenders a way to test visibility for this privilege-escalation pattern, although the analytic is disabled by default and generates intermediate risk events rather than direct notable alerts.
Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.
Threat actors have been targeting poorly secured, internet-exposed Microsoft SQL Server instances to deliver Mimic and Trigona ransomware, using brute-force or weak credentials and, in some cases, xp_cmdshell for command execution. Researchers reported that one actor used the SQL Server Bulk Copy Program (BCP) utility to rebuild malware from database contents onto disk, while other intrusions relied on PowerShell download cradles, mounted SMB shares, and remote access tools including AnyDesk. In multiple cases, the attackers established persistence, created administrator accounts, enabled credential theft opportunities such as the WDigest\UseLogonCredential registry setting, and deployed tooling including Mimikatz, PsExec, Advanced Port Scanner, Defender Control, and SDelete.
Attackers used spoofed Government of India GST refund emails to target Indian businesses and taxpayers, luring recipients into opening a malicious RAR attachment that launched a multi-stage .NET infection chain and ultimately deployed Remcos RAT. Seqrite reported that the initial executable unpacked successive in-memory loaders hidden in bitmap resources and DLL stages, including Windows Health Optimizer Plus.dll and perfgurd.dll, while using reflection, XOR-based decryption, and architecture-aware method dispatch to evade analysis and execute the final payload. The campaign established persistence by copying the executable and launching a PowerShell script through a Run registry key, and it attempted privilege escalation via cmstp.exe. The final Remcos RAT payload enabled remote access, credential theft, surveillance, and delivery of additional malware. Infrastructure tied to the operation included dynamic DNS domains under hath.network and synology.me, with command-and-control activity resolving to 185.242.4.122 on hosting associated with M247 Europe SRL; researchers assessed the activity as likely financially motivated cybercrime but did not attribute it to a known threat actor.
Cisco Talos reported that Russian-speaking threat actor UAT-11795 has run a financially motivated malware campaign since at least June 2025, primarily targeting users in the United States and also affecting victims in Germany, Romania, and Venezuela. The operation uses ClickFix-style lures, weaponized HTA files, and trojanized NSIS installers masquerading as legitimate software such as Zoom and Webex to deliver a Python-based backdoor dubbed Starland RAT. Talos said the malware establishes persistence, performs sandbox checks, and collects extensive host, browser, Active Directory, credential, and cryptocurrency wallet data. Researchers said Starland RAT also supports remote command execution, screenshot capture, shellcode injection, and delivery of follow-on payloads including CastleStealer and Remcos RAT. Talos additionally identified a bespoke in-memory PowerShell implant called WLDR, which uses encrypted command-and-control tied to a victim hardware identifier for reconnaissance and modular tasking. The campaign relies on distributed staging and C2 infrastructure, including Telegram bots for execution alerts and victim profiling, and a Polygon smart contract that provides a fallback mechanism for resolving C2 domains when primary infrastructure is disrupted.
A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.