Last seven days
- First activity
- Jul 31, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 112 IP / 117 hostnames
Remcos RAT is a Windows remote access trojan originally developed as a legitimate remote administration tool and later widely abused in criminal intrusion, phishing, and surveillance operations.
Profile source: Mallory opens in a new tabRemcos
Remcos RAT is a Windows remote access trojan originally developed as a legitimate remote administration tool and later widely abused in criminal intrusion, phishing, and surveillance operations. It provides persistent backdoor access that enables remote control of compromised systems and is commonly associated with credential theft, keylogging, screen capture, and broader post-compromise activity. Reported operator use also includes deployment as a supplemental payload in multi-stage intrusion chains and as a second-stage implant delivered by loaders, shellcode launchers, or other malware frameworks.
Observed delivery has been dominated by phishing and malspam campaigns using business-themed lures, malicious archives, LNK files, script-based stages, and weaponized Microsoft Office documents. Historical exploitation of CVE-2017-0199 and CVE-2017-11882 has been associated with Remcos delivery, and more recent campaigns have used trojanized installers, WebDAV-retrieved payloads, and disguised loader chains that execute the RAT in memory. Remcos has also appeared as a payload protected or distributed by crypter services such as Cruciferra and in campaigns using fake update or document/payment themes.
On infected hosts, Remcos has been observed establishing persistence through mechanisms including scheduled tasks, Startup folder shortcuts, and Run-key style autoruns in broader delivery chains. It has been linked to dynamic DNS-backed command-and-control, remote command execution, file management, screenshot capture, real-time monitoring, and theft of sensitive information. Defensive reporting also ties Remcos activity to memory-resident execution and to defense-evasion behavior in some campaigns, including ETW patching attempts detected by kernel-level monitoring.
Remcos is used broadly across commodity cybercrime and has been observed in campaigns targeting sectors including finance, education, professional services, hospitality, government-related themes, and cryptocurrency-focused victims. It has also been linked in reporting to activity associated with APT-C-36 and has been used by financially motivated operators as part of larger intrusion ecosystems alongside stealers and other RAT families.
C2 tracking
Derp observations, rolling seven-day window
Samples
f058ffbf0494bb237f5fd7fd6564a6442598c44542e03a49fd2e82888fab6046 aa0049ae7a554a0377ae51c767111bbfd693558cf8e6990ab26af068a774e1d8 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 6747147c5ba29975a557d88cd22114478890a0a0a613f36512dcb730e4efe965 944a6ff7edb3991a3f60e19d26f23ad21054adc53109cfcdbb5d101a84a7971b dd17e871204619a3de34126e366221b64e684ec13e24dfc871698abe343acbff fbf4ef28c4b49c6304d23a738afabf8981590eae8585834bf24e3c7e87163c1a 2f029858b8ecca8fb6c156eb2d046a2463e8b67d356c1003e5567339681a71be 4fe508025770c53e0717b524175f079ee23443a4ed909a36be04ee7522e7e055 9bb943340f1b6bf6cff15334ab9b0ab32740455f50f76a779f1735445cb521ae Reported operators
Depending on operator objectives, Starland RAT can deploy CastleStealer, Remcos RAT, or the previously undocumented WLDR framework.
COLCERT AL โ 20260801 - 104 Alerta: Actividad de Remcos RAT vinculada a APT-C-36
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
[๐ฝTA] TA558 (๐ด): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
The modular HijackLoader bundle decodes Remcos Agent 7.1.0 Pro, configured to communicate with the same server that delivered the initial PowerShell stages and secondary archive: 144.31.236.240:27018
The modular HijackLoader bundle decodes Remcos Agent 7.1.0 Pro, configured to communicate with the same server that delivered the initial PowerShell stages and secondary archive: 144.31.236.240:27018
The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
TA2722 distributes Remcos and NanoCore remote access trojans (RATs). Remcos and NanoCore are typically used for information gathering, data theft operations, monitoring and control of compromised computers.
Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.
Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.
Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
In a shift from Scarlet Goldfinchโs usual payload, the malicious DLL sideloads the Remcos remote access tool, replacing the expected NetSupport Manager.
Remcos has a command to hide itself through injecting into another process.
Remcos (Backdoor.Remvio): A commodity remote administration tool (RAT) that can be used to steal information from an infected computer.
MITRE ATT&CK Technique Malware Families T1105 ... Remcos ... T1547.001 ... Remcos ... T1056.001 ... Remcos ...
The attackers typically use targeted phishing emails with malicious files disguised as legitimate documents to gain initial access, and deploy backdoors such as BrockenDoor, as well as other malware including Remcos and DarkGate.
This was the first time Proofpoint observed UAC-0050 deliver NetSupport, as it has historically used other malware including Remcos and Lumma Stealer, but it has previously used RMMs including Litemanager and Remote Manipulator System (RMS).
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.
The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...
"Some of the payloads identified for campaign 2... included... RAT Remcos"
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.
This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.
Exploited software
MITRE ATT&CK
Reporting
Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.
Attackers used spoofed Government of India GST refund emails to target Indian businesses and taxpayers, luring recipients into opening a malicious RAR attachment that launched a multi-stage .NET infection chain and ultimately deployed Remcos RAT. Seqrite reported that the initial executable unpacked successive in-memory loaders hidden in bitmap resources and DLL stages, including Windows Health Optimizer Plus.dll and perfgurd.dll, while using reflection, XOR-based decryption, and architecture-aware method dispatch to evade analysis and execute the final payload. The campaign established persistence by copying the executable and launching a PowerShell script through a Run registry key, and it attempted privilege escalation via cmstp.exe. The final Remcos RAT payload enabled remote access, credential theft, surveillance, and delivery of additional malware. Infrastructure tied to the operation included dynamic DNS domains under hath.network and synology.me, with command-and-control activity resolving to 185.242.4.122 on hosting associated with M247 Europe SRL; researchers assessed the activity as likely financially motivated cybercrime but did not attribute it to a known threat actor.
Cisco Talos reported that Russian-speaking threat actor UAT-11795 has run a financially motivated malware campaign since at least June 2025, primarily targeting users in the United States and also affecting victims in Germany, Romania, and Venezuela. The operation uses ClickFix-style lures, weaponized HTA files, and trojanized NSIS installers masquerading as legitimate software such as Zoom and Webex to deliver a Python-based backdoor dubbed Starland RAT. Talos said the malware establishes persistence, performs sandbox checks, and collects extensive host, browser, Active Directory, credential, and cryptocurrency wallet data. Researchers said Starland RAT also supports remote command execution, screenshot capture, shellcode injection, and delivery of follow-on payloads including CastleStealer and Remcos RAT. Talos additionally identified a bespoke in-memory PowerShell implant called WLDR, which uses encrypted command-and-control tied to a victim hardware identifier for reconnaissance and modular tasking. The campaign relies on distributed staging and C2 infrastructure, including Telegram bots for execution alerts and victim profiling, and a Polygon smart contract that provides a fallback mechanism for resolving C2 domains when primary infrastructure is disrupted.
A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.
Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.