Remcos RAT is a commercial Windows remote-access trojan marketed by Breaking Security that has been repeatedly abused in criminal malware operations. It provides remote control of compromised hosts and can capture screenshots, modify the Windows Registry, and conceal windows to reduce user visibility. It has been observed as a payload in multi-stage loader chains, including .NET-based GraftLoader deployments using in-memory execution and process hollowing. Remcos RAT is also distributed through malspam, including Italian-language business-themed email campaigns using payment, request, order, receipt, and document lures. APT-C-36 (Blind Eagle) has used Remcos RAT among its commodity remote-access tooling in campaigns targeting Colombia and other South American organizations. Victim sectors associated with APT-C-36 activity include government, finance, healthcare, telecommunications, energy, and oil and gas. Remcos RAT infrastructure has additionally appeared in broader criminal command-and-control ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Actors (TAs) leveraging a Remote Code Execution (RCE) vulnerability, identified as CVE-2023-38831, to deliver their payload on compromised systems... The aforementioned vulnerability allows the WinRAR application to extract and execute the malicious script when a user tries to open a benign file within the archive. | Moreover, they observed that several other malware families, including GuLoader and Remcos RAT, were also utilizing the same exploit as a means of delivery.
In 2017, we reported spotting Remcos being delivered via a malicious PowerPoint slideshow, embedded with an exploit for CVE-2017-0199. | In July, we came across a phishing email purporting to be a new order notification, which contains a malicious attachment that leads to the remote access tool Remcos RAT... This attack delivers Remcos using an AutoIt wrapper that incorporates various obfuscation and anti-debugging techniques to evade detection.
The malicious Excel file exploits a vulnerability in Microsoft Office Equation editor called CVE-2017-11882. It downloads an executable from http://136[.]144[.]41[.]109/HRE[.]exe. Finally, this executable file downloads the final payload, which is Remcos. | Finally, this executable file downloads the final payload, which is Remcos. Remcos is a remote access Trojan (RAT) that can give an attacker full control over its target’s system.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
And sure enough, the MD5 of the file {CACAF1F7-CE7C-4CA2-B9E3-ABBC9F6E965D}.exe maps to a file on VirusTotal named Erlianaw.exe, the filename we saw earlier during the analysis of the LNK file. Figure 5: Erlianaw.exe - Remcos on VirusTotal
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
50 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Campaign 2 payload is Remcos, the commercial remote administration tool sold by Breaking Security.”
“In the past, we have observed that APT-C-36 makes use of RATs such as: ... Remcos RAT ...”
к доменам хак-группы обращались более 31 000 образцов вредоносов, включая Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT и njRAT
Later, on November 12th, 2024, another spam campaign was launched ... Inside this RAR archive could be found a 32-bit executable Remcos payload that would communicate with its C2 on IP ‘111.90.140[.]65:2404’ and botnet ID “hstnw”.
The campaign included the use of a variant of AZORult, an information-stealing malware; as well as the RAT Remcos; the DarkVNC backdoor trojan; and a clipboard cryptocurrency stealer.
To give an overview, here is a list of all observed tools and malware types the actor has been using in recent years: Remcos RAT
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The ransomware campaign crafted a malicious website mimicking the IFP site, along with a slight variation of the IFP site domain name.
The Italian campaigns were grouped according to macro categories obtained from the subject of the email message used for malware distribution (malspam). Campaign subjects included Reservations, Requests, Orders, and Payments.
Remote Shell Access Establish a remote shell and execute system commands on the infected machine | Script Execution Execute JavaScript, VBS, or batch scripts remotely for additional malicious operations
“A self-extracting archive launched VBScript and hidden PowerShell, wrote script content into ProgramData, then reached InstallUtil.exe.”
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL is capable of setting and deleting Registry values. Agent Tesla can achieve persistence by modifying Registry key entries. APT41 used a malware variant called GOODLUCK to modify the registry in order to steal credentials.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
さらにこの PowerShell スクリプトは、変数 codigo に格納された難読化された文字列に対して、文字列 DgTre を文字 A に置換する処理を行った後、Base64 デコードして PowerShell スクリプトを実行します。
We discuss two prevalent such packers used to distribute a wide variety of malware but hiding the intended payload in images. | In a recent variation of this packer, the first stage payload is actually stored in a second PNG image extracted from the least significant bits of the Red, Green, and Blue channels in the first image.
“[The chain] then reached InstallUtil.exe, a signed Windows utility that can be abused to run malicious code.”
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
часть инфраструктуры Sable Squirrel используется для работы малвари: к доменам хак-группы обращались более 31 000 образцов вредоносов... некоторые сайты одновременно показывали посетителям спортивные трансляции и работали в качестве управляющих серверов для малвари.
“Related samples contacted code repositories and cloud storage” and “The operation can move files between familiar services.”
1,493 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote-access malware found among recovered campaign artifacts; its presence suggests the operator maintained multiple potential payload options.
Remote-access trojan for which the recovered workstation contained a build folder and apparent system-information collection artifacts from multiple infected hosts.
A commercial remote-access tool used as GraftLoader's Campaign 2 final payload. The recovered configuration identifies primary and secondary C2 endpoints, campaign tag Rmc-T423KN, installation name remcos.exe, and keylogging configuration. Its capabilities include keylogging, clipboard collection, screen capture, and microphone capture.
Remote-access trojan previously used by APT-C-36.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.