Skip to content

Remcos

Remcos RAT is a Windows remote access trojan originally developed as a legitimate remote administration tool and later widely abused in criminal intrusion, phishing, and surveillance operations.

Profile source: Mallory opens in a new tab

Remcos

Family profile

Remcos RAT is a Windows remote access trojan originally developed as a legitimate remote administration tool and later widely abused in criminal intrusion, phishing, and surveillance operations. It provides persistent backdoor access that enables remote control of compromised systems and is commonly associated with credential theft, keylogging, screen capture, and broader post-compromise activity. Reported operator use also includes deployment as a supplemental payload in multi-stage intrusion chains and as a second-stage implant delivered by loaders, shellcode launchers, or other malware frameworks.

Observed delivery has been dominated by phishing and malspam campaigns using business-themed lures, malicious archives, LNK files, script-based stages, and weaponized Microsoft Office documents. Historical exploitation of CVE-2017-0199 and CVE-2017-11882 has been associated with Remcos delivery, and more recent campaigns have used trojanized installers, WebDAV-retrieved payloads, and disguised loader chains that execute the RAT in memory. Remcos has also appeared as a payload protected or distributed by crypter services such as Cruciferra and in campaigns using fake update or document/payment themes.

On infected hosts, Remcos has been observed establishing persistence through mechanisms including scheduled tasks, Startup folder shortcuts, and Run-key style autoruns in broader delivery chains. It has been linked to dynamic DNS-backed command-and-control, remote command execution, file management, screenshot capture, real-time monitoring, and theft of sensitive information. Defensive reporting also ties Remcos activity to memory-resident execution and to defense-evasion behavior in some campaigns, including ETW patching attempts detected by kernel-level monitoring.

Remcos is used broadly across commodity cybercrime and has been observed in campaigns targeting sectors including finance, education, professional services, hospitality, government-related themes, and cryptocurrency-focused victims. It has also been linked in reporting to activity associated with APT-C-36 and has been used by financially motivated operators as part of larger intrusion ecosystems alongside stealers and other RAT families.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 31, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
112 IP / 117 hostnames

Leading locations

  • US65
  • NL19
  • DE17
  • TR11
  • CN10
  • LU7
  • FR5
  • GB5
  • IT5
  • CO4
  • CA3
  • ES3

Leading providers

  • HostPapa24
  • Fiba Cloud Operation Company, LLC13
  • Ghosty Networks LLC11
  • M247 Europe SRL9
  • 1337 Services GmbH5
  • RACK SPHERE HOSTING S.A.5

Infrastructure traits

  • Hosting 171
  • Vpn 10
  • Anycast 5
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

57 named in public reporting
UAT-11795

Depending on operator objectives, Starland RAT can deploy CastleStealer, Remcos RAT, or the previously undocumented WLDR framework.

APT-C-36

COLCERT AL โ€“ 20260801 - 104 Alerta: Actividad de Remcos RAT vinculada a APT-C-36

Mysterious Elephant

The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.

Bitter

The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.

TAG-179

The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.

SideWinder

Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.

Confucius

Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.

TA558

[๐Ÿ‘ฝTA] TA558 (๐Ÿด): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)

UAC-0184

The modular HijackLoader bundle decodes Remcos Agent 7.1.0 Pro, configured to communicate with the same server that delivered the initial PowerShell stages and secondary archive: 144.31.236.240:27018

MB-0005

The modular HijackLoader bundle decodes Remcos Agent 7.1.0 Pro, configured to communicate with the same server that delivered the initial PowerShell stages and secondary archive: 144.31.236.240:27018

SmartApeSG

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

TA2722

TA2722 distributes Remcos and NanoCore remote access trojans (RATs). Remcos and NanoCore are typically used for information gathering, data theft operations, monitoring and control of compromised computers.

SilverTerrier

Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.

BoredFluff

Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.

BlackToad

Security professionals recently discovered a highly dangerous malicious email operation targeting corporate networks. Specifically, threat actors initiated a sophisticated Remcos RAT phishing campaign... This structural evolution within the Remcos RAT phishing campaign allows the primary remote access trojan module to initialize smoothly.

Gorgon Group

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

Scarlet Goldfinch

In a shift from Scarlet Goldfinchโ€™s usual payload, the malicious DLL sideloads the Remcos remote access tool, replacing the expected NetSupport Manager.

Gamaredon Group

Remcos has a command to hide itself through injecting into another process.

APT33

Remcos (Backdoor.Remvio): A commodity remote administration tool (RAT) that can be used to steal information from an infected computer.

FIN7

MITRE ATT&CK Technique Malware Families T1105 ... Remcos ... T1547.001 ... Remcos ... T1056.001 ... Remcos ...

BO Team

The attackers typically use targeted phishing emails with malicious files disguised as legitimate documents to gain initial access, and deploy backdoors such as BrockenDoor, as well as other malware including Remcos and DarkGate.

UAC-0050

This was the first time Proofpoint observed UAC-0050 deliver NetSupport, as it has historically used other malware including Remcos and Lumma Stealer, but it has previously used RMMs including Litemanager and Remote Manipulator System (RMS).

ZPHP

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

HANEYMANEY

The campaign, active as recently as March 24, 2026, delivered four separate malware payloads to a single infected host in one session: Remcos RAT, NetSupport RAT, StealC, and Sectop RAT, also known as ArechClient2.

Prince of Persia

The expanded toolkit in this phase incorporated commodity tools such as Remcos RAT, Stealerium, StormKitty, and ZZ Stealer...

RATicate

"Some of the payloads identified for campaign 2... included... RAT Remcos"

BRONZE BUTLER

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Blue Mockingbird

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Dark Caracal

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

WIZARD SPIDER

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Group5

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

TA505

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Kimsuky

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

APT32

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

MoustachedBouncer

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Medusa Group

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

INDRIK SPIDER

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

APT41

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Lotus Blossom

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

OilRig

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Dragonfly

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

APT39

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

FIN8

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

GOLD SOUTHFIELD

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Winter Vivern

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Turla

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Silence

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Volt Typhoon

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

Ember Bear

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

BlackByte

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Threat Group-3390

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Mustang Panda

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Magic Hound

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Patchwork

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

MuddyWater

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

APT42

This activity is significant as it indicates the presence of the Remcos RAT, which performs keylogging, clipboard capturing, and audio recording.

APT38

This behavior is significant as it indicates potential compromise by the Remcos RAT, a remote access Trojan used for unauthorized access and data exfiltration.

Exploited software

Vulnerabilities linked to Remcos

6 CVEs

MITRE ATT&CK

Remcos in ATT&CK

95 distinct techniques

Techniques

95 techniques
T1620 Reflective Code Loading T1140 Deobfuscate/Decode Files or Information T1562 Impair Defenses T1055 Process Injection T1566.001 Spearphishing Attachment T1566 Phishing T1562.002 Disable Windows Event Logging T1105 Ingress Tool Transfer T1218.011 Rundll32 T1204 User Execution T1204.001 Malicious Link T1071 Application Layer Protocol T1568 Dynamic Resolution T1027 Obfuscated Files or Information T1203 Exploitation for Client Execution T1539 Steal Web Session Cookie T1219 Remote Access Tools T1036 Masquerading T1059.005 Visual Basic T1123 Audio Capture T1113 Screen Capture T1555 Credentials from Password Stores T1204.002 Malicious File T1548.002 Bypass User Account Control T1573 Encrypted Channel T1572 Protocol Tunneling T1497 Virtualization/Sandbox Evasion T1056.001 Keylogging T1547.001 Registry Run Keys / Startup Folder T1021 Remote Services T1053 Scheduled Task/Job T1055.012 Process Hollowing T1622 Debugger Evasion T1543.003 Windows Service T1059.007 JavaScript T1218 System Binary Proxy Execution T1127.001 MSBuild T1059.001 PowerShell T1059 Command and Scripting Interpreter T1059.003 Windows Command Shell T1566.002 Spearphishing Link T1553.002 Code Signing T1059.010 AutoHotKey & AutoIT T1129 Shared Modules T1027.013 Encrypted/Encoded File T1057 Process Discovery T1082 System Information Discovery T1083 File and Directory Discovery T1489 Service Stop T1071.001 Web Protocols T1016 System Network Configuration Discovery T1218.003 CMSTP T1005 Data from Local System T1039 Data from Network Shared Drive T1562.001 Disable or Modify Tools T1115 Clipboard Data T1125 Video Capture T1047 Windows Management Instrumentation T1027.003 Steganography T1596.005 Scan Databases T1596.001 DNS/Passive DNS T1190 Exploit Public-Facing Application T1102.001 Dead Drop Resolver T1195 Supply Chain Compromise T1560 Archive Collected Data T1564 Hide Artifacts T1189 Drive-by Compromise T1112 Modify Registry T1555.003 Credentials from Web Browsers T1041 Exfiltration Over C2 Channel T1074 Data Staged T1070.004 File Deletion T1070 Indicator Removal T1218.005 Mshta T1102 Web Service T1497.001 System Checks T1560.001 Archive via Utility T1564.001 Hidden Files and Directories T1588.001 Malware T1027.001 Binary Padding T1583.006 Web Services T1048 Exfiltration Over Alternative Protocol T1486 Data Encrypted for Impact T1059.006 Python T1012 Query Registry T1218.010 Regsvr32 T1571 Non-Standard Port T1547.009 Shortcut Modification T1001.003 Protocol or Service Impersonation T1132 Data Encoding T1027.007 Dynamic API Resolution T1588.002 Tool T1001.001 Junk Data T1657 Financial Theft T1548 Abuse Elevation Control Mechanism

Reporting

Research mentioning Remcos

Jul 27
Netresec

PureLogs, PureRAT and misleading zgRAT

Security researchers and email threat monitors reported continued activity from the PureCoder malware ecosystem, with campaigns distributing credential-stealing and remote-access payloads including PureLogs, PureRAT, and PureHVNC. An analysis of the broader Pure malware family described it as a growing threat, while Italian malspam telemetry later showed PureHVNC appearing alongside AgentTesla, FormBook, and Remcos in business-themed phishing lures tied to bank transfers, orders, offers, and requests. Script files were the most common attachment type in those campaigns, followed by Office documents and MSIL binaries. Researchers also warned that industry naming around this malware remains inconsistent, especially the use of zgRAT to describe different PureCoder families. Netresec said the label is being applied to both PureLogs, a .NET infostealer focused on credential and data theft, and PureRAT, a .NET RAT that supports capabilities such as HVNC, webcam and microphone access, keylogging, reverse proxying, and code injection. The report said this overlap affects Suricata and TLS-certificate-based detections, creating false positives and family-level misclassification, and urged defenders to use precise names such as PureLogs or PureRAT when attribution is clear.

Jul 23
Security Online Info

GST Phishing Campaign Distributes Remcos RAT Malware

Attackers used spoofed Government of India GST refund emails to target Indian businesses and taxpayers, luring recipients into opening a malicious RAR attachment that launched a multi-stage .NET infection chain and ultimately deployed Remcos RAT. Seqrite reported that the initial executable unpacked successive in-memory loaders hidden in bitmap resources and DLL stages, including Windows Health Optimizer Plus.dll and perfgurd.dll, while using reflection, XOR-based decryption, and architecture-aware method dispatch to evade analysis and execute the final payload. The campaign established persistence by copying the executable and launching a PowerShell script through a Run registry key, and it attempted privilege escalation via cmstp.exe. The final Remcos RAT payload enabled remote access, credential theft, surveillance, and delivery of additional malware. Infrastructure tied to the operation included dynamic DNS domains under hath.network and synology.me, with command-and-control activity resolving to 185.242.4.122 on hosting associated with M247 Europe SRL; researchers assessed the activity as likely financially motivated cybercrime but did not attribute it to a known threat actor.

Jul 22
Security Online Info

Starland RAT: Russian Actor UAT-11795 Hits Crypto Users

Cisco Talos reported that Russian-speaking threat actor UAT-11795 has run a financially motivated malware campaign since at least June 2025, primarily targeting users in the United States and also affecting victims in Germany, Romania, and Venezuela. The operation uses ClickFix-style lures, weaponized HTA files, and trojanized NSIS installers masquerading as legitimate software such as Zoom and Webex to deliver a Python-based backdoor dubbed Starland RAT. Talos said the malware establishes persistence, performs sandbox checks, and collects extensive host, browser, Active Directory, credential, and cryptocurrency wallet data. Researchers said Starland RAT also supports remote command execution, screenshot capture, shellcode injection, and delivery of follow-on payloads including CastleStealer and Remcos RAT. Talos additionally identified a bespoke in-memory PowerShell implant called WLDR, which uses encrypted command-and-control tied to a victim hardware identifier for reconnaissance and modular tasking. The campaign relies on distributed staging and C2 infrastructure, including Telegram bots for execution alerts and victim profiling, and a Polygon smart contract that provides a fallback mechanism for resolving C2 domains when primary infrastructure is disrupted.

Jul 22
Security Online Info

TTF Trap: Fake Font Files Hide a Stealthy Lua Loader

A global phishing campaign dubbed TTF Trap is using business email compromise lures and impersonation of trusted brands such as FedEx to infect Windows users with remote access Trojans and infostealers. Fortinet said the operation begins with phishing emails carrying or linking to ZIP or RAR archives, then launches heavily obfuscated JavaScript that establishes persistence and triggers a disguised loader hidden inside a fake .ttf font file. The loader runs through legitimate LuaJIT or AutoIt interpreters and uses layered obfuscation, in-memory execution, API unhooking, anti-analysis checks, and reflective loading to avoid detection while keeping payloads off disk. Researchers observed the campaign since late March and said related loader code dates back to October 2025; malware delivered in the operation includes Agent Tesla, Remcos, XWorm, Best Private Logger, and Snake Keylogger variants, with the apparent goal of stealing data and maintaining remote access for follow-on attacks.

Jul 21
Cyber Security News

This $2,000-a-Month Crypter Can Kill EDR and Make Malware Disappear From Disk

Proofpoint reported that the Cruciferra crypter-as-a-service is being used by multiple unrelated cybercriminal actors to deliver commodity malware, particularly RATs and infostealers, through email-borne campaigns. Marketed since fall 2025 on exploit[.]in with subscription tiers ranging from $450 to $2,000 per month, the service has been tied to campaigns distributing AsyncRAT, XWorm, zgRAT, Agent Tesla, Formbook, XLoader, Phantom Stealer, and Remcos. Financial services, healthcare, and government organizations appeared frequently among targets, while observed lures included tax-themed messages linked to TA4922 and hospitality-themed campaigns delivering zgRAT. Researchers said Cruciferra is under active development, with both production and testing variants observed and VirusTotal metadata indicating frequent rebuilds and redeployment. The crypter, written in Mono, combines layered evasion and anti-analysis techniques including DLL side-loading, decoy exports, indirect syscalls, API and IAT unhooking, BYOVD-based EDR tampering, persistence, UAC bypass, and a customized Process Ghosting implementation, alongside more than 90 custom or hybrid cryptographic routines designed to conceal payloads and hinder static analysis. Microsoft documentation on the COM Elevation Moniker provides context for one of the Windows privilege-elevation mechanisms relevant to the UAC bypass tradecraft described in the analysis.

Jul 21
Scworld

Sophisticated crypter service Cruciferra evades detection with advanced techniques | brief | SC Media

Jul 21
Gurucul Threat Research

Unpacking โ€œCruciferraโ€: An Analysis of a Sophisticated Crypter Service | Community Portal | Gurucul

Jul 20
Dark Reading

Attackers Combo Up Evasion Tactics for BEC Phishing

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.