Remcos RAT is a Windows remote access trojan widely used in cybercrime and also observed in some espionage-linked intrusions. It is commonly delivered through phishing and malspam campaigns using business, payment, invoice, survey, or government-themed lures, and has also appeared as a follow-on payload in multi-stage intrusion chains involving trojanized installers, shellcode loaders, HTA or script-based stagers, and fileless .NET, PowerShell, AutoIt, Lua, or JScript execution paths. Observed campaigns have used obfuscation, in-memory loading, process injection, privilege escalation, and persistence mechanisms to deploy Remcos while reducing detection.
Once installed, Remcos provides full remote control of an infected system and supports post-compromise surveillance and operator tasking. Reported capabilities include remote command execution, file manipulation and transfer, keylogging, screenshot capture, clipboard monitoring, audio recording, webcam access, registry modification, reconnaissance, and collection of system and user information. It is frequently used to expand post-exploitation capability after initial access and can support credential theft and data exfiltration through its command-and-control channel.
Recent activity shows Remcos used in large-scale global phishing operations, GST-themed campaigns targeting Indian businesses and taxpayers, payment-themed phishing targeting Korean recipients, Italian malspam activity, and intrusions affecting Pakistani law enforcement organizations. It has also been deployed by the financially motivated, Russian-speaking actor UAT-11795 as an additional payload alongside Starland RAT, WLDR, and CastleStealer, and Remcos-related activity in Pakistani law enforcement intrusions has been linked to an India-nexus cluster overlapping with TAG-179 or Mysterious Elephant reporting. The malware remains a common commodity RAT in both broad criminal distribution and targeted operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, the document contains the CVE-2017-0199 vulnerability, which exploits OLE objects. This vulnerability is a remote code execution (RCE) flaw that exploits the OLE2Link feature in Microsoft Office; when a user opens the document, it automatically accesses an external URL to download and execute additional Malicious Files (such as HTA files). | At this point, the loader operates by receiving the C2 server address—from which it will download the Remcos RAT—as an argument value. Ultimately, the Remcos RAT is malware that receives and executes remote commands on an infected system; it collects system and user information through various functions such as keylogging, screen capture, and file manipulation.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
...triggers an exploit for a years-old security flaw in Microsoft Office (CVE-2017-11882) to distribute a new variant of Remcos RAT...
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
Group-IB Threat Intelligence unit discovered a zero-day vulnerability, CVE-2023-38831, in WinRAR, a popular compression tool. Cybercriminals exploited this vulnerability to deliver various malware families, including DarkMe and GuLoader, by crafting ZIP archives with spoofed extensions. | The malware was distributed alongside other malware families, such as GuLoader and Remcos RAT, via malicious ZIP archives posted on popular trading forums or distributed via file-sharing services.
58 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group also uses CastleStealer and Remcos RAT as additional payloads to expand its post-compromise capabilities.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
It then generates a PowerShell script (.ps1) in the temporary directory, which is responsible for launching the copied executable in hidden mode.
These decoded strings are subsequently used by the second-stage assembly as command or operation identifiers... perform an injection-related operation (inj).
Although the function contains a large amount of obfuscating junk code...
The author hides it inside the image by encoding the payload bytes into the RGB values of the bitmap’s pixels.
Upon extraction, the archive contained an executable file masquerading as a GST refund-related document or application.
These decoded strings are subsequently used by the second-stage assembly as command or operation identifiers... perform an injection-related operation (inj).
The extracted payload is processed through a custom XOR-based decryption routine... After decryption, the payload is reconstructed directly in memory.
The analyzed sample provides capabilities commonly associated with Remcos RAT, including: ... Collection of system and network information.
The analyzed sample provides capabilities commonly associated with Remcos RAT, including: ... Process and service manipulation.
Remcos Capabilities: ... File upload and download... Credential harvesting... Collection of system and network information.
828 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commercially available remote administration tool abused as malware to establish persistent remote access, execute commands, manage files, log keystrokes, harvest credentials, capture screenshots, perform reconnaissance, manipulate processes/services/registry, communicate with C2, and deploy additional payloads.
A commercially available remote administration tool abused as malware to establish persistent remote access, execute commands, manage files, log keystrokes, harvest credentials, perform reconnaissance, manipulate processes/services/registry, capture screenshots, provide remote desktop access, communicate with C2 infrastructure, and deploy additional payloads.
A remote access trojan delivered as an additional payload through Starland via a separate 32-bit shellcode path.
A remote access trojan used as an additional payload to expand post-compromise access and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.