RemcosRAT is a commercial Windows remote access trojan widely used in both cybercrime and espionage operations. It provides operators with persistent remote control of infected systems and has been observed in campaigns targeting government entities, military-related personnel, financial institutions, and other organizations. Reported functionality includes remote command execution, file transfer, surveillance, screenshot capture, keylogging, audio or microphone capture, and theft of browser-stored data and other victim information. Some observed configurations also support collection of credentials and session-related browser artifacts.
The malware is frequently delivered through multi-stage infection chains that rely on social engineering and commodity loaders. Documented delivery mechanisms include phishing and spearphishing lures, malicious shortcut files, HTML smuggling, HTA and JavaScript droppers, MSI installers, AutoIt-based loaders, and loader families such as GuLoader, GoLoader, Amadey, and other staging components. It has also been observed in campaigns using DLL sideloading and in-memory execution techniques to reduce detection.
RemcosRAT commonly employs defense-evasion and persistence mechanisms. Observed tradecraft includes encrypted configuration storage in resources, obfuscated scripts, process hollowing or memory-only execution chains, use of unnamed pipes to transfer decrypted payloads between processes, and persistence via startup entries, scheduled tasks, or copied payloads in user-writable locations. Campaigns have also used legitimate interpreters and signed binaries to proxy execution.
The malware has been linked to a broad range of threat activity rather than a single actor. It has appeared in operations attributed to groups such as UAC-0050, UAC-0184, Black Basta-associated intrusion chains, and Konni-linked activity, as well as in commodity malware distribution ecosystems and pay-per-install services. Its prevalence across criminal and state-linked operations reflects its accessibility as a commercial RAT and its flexibility for surveillance, credential theft, post-compromise control, and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s weapon of choice is RemcosRAT, a notorious malware for remote surveillance and control... Analysis revealed UAC-0050's deployment of RemcosRAT in a targeted cyber intelligence operation against Ukrainian government agencies.
During 2019-2021 I was focused on analyzing campaigns orchestrated by the APT-C-36 group and RATs used by this same group and other cybercriminal groups such as RemcosRAT, AsyncRAT, Imminent Monitor RAT, etc.
The threat actor used an AutoIt script to launch RemcosRAT (Remote Access Trojan). On some victims’ systems, RemcosRAT 7.0.4 Pro was identified, indicating that the attackers were actively using the latest malware and tactics.
The files distributed were malicious AutoIt scripts and modules that enable remote access and keylogging, as well as various RATs, including LilithRAT and RemcosRAT.
Red Akodon targets users... using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT, and XWorm.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
eSentire has observed a substantial increase in malware being delivered through tax-themed phishing emails. Cybercriminals are exploiting the urgency and importance of tax-related communications to trick individuals into opening malicious email links, leading to malware infections.
Inside there is a Visual Basic Script (VBS) file... Then PowerShell is executed and passing an encoded command.
Following the successful deobfuscation of the VBScript, we obtained a PowerShell script... It uses the | powershell - syntax to execute the decrypted payload as a new PowerShell process.
Upon launching, word_update.exe executes cmd.exe and shares malicious data through a pipe.
Inside there is a Visual Basic Script (VBS) file called Fiche de candidature .vbs which is executed when double-clicked.
Towards the end of the .lnk file, the threat actor has obfuscated the URL string... the 6.hta file... contains a VBScript file with fully obfuscated script content.
the threat actor attempted to deliver malware using HTML smuggling, a technique for sneaking malicious email attachments past gateway security controls.
6ca7a458985350ac082a9c9820d7f8d39128a4c4bda2f5d32f169a45b7b22bc6 MobaXterm_v26.1.exe ... 6ae334ce60d1a9b7fb96d1d0d0eda5ec7c2c31d3f0cf3e4d7e3056504d50043d WebEx_Client.exe ... 1a01ad25712d306f27f526332fdccf959f2de53207b54e4e80f60faa804d6cb6 FaceitInstaller_x64.exe ... f4491736743a16f1278b8ba01649ee93343764e35ae5e1c0d5e0c0e1d7e32c14 Zoom Installer
219 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan family included in the classifier’s malware classes.
Remote access trojan referenced among malware samples, associated here with IMG and CAB formats.
A remote access trojan mentioned as one of the payloads delivered by PhantomVAI in other campaigns.
A commercial remote access trojan abused in cybercrime campaigns. In this campaign it is delivered through a four-stage chain, process-hollowed into Aspnet_compiler.exe, and used for surveillance and remote control including keylogging, camera access, audio recording, screenshots, file management, command execution, and watchdog behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.