RemcosRAT is a full remote access trojan (RAT) observed across both commodity cybercrime and targeted intrusion campaigns. The content links it to multiple delivery chains and operators, including Konni activity assessed as North Korean-linked, UAC-0184 targeting Ukraine’s Defense Forces, Red Akodon and Shadow Vector campaigns targeting users in Colombia, and broader criminal distribution ecosystems such as Amadey and GoLoader. It is also referenced in activity associated with UAC-0050 attacks targeting Ukraine and a European financial institution.
Observed infection vectors include spear-phishing emails, malicious LNK files in ZIP archives, HTA droppers executed via mshta.exe, JavaScript droppers, MSI installers, SVG-based phishing chains, AutoIt-based loaders, DLL sideloading with signed VMware and Microsoft Edge binaries, and staged payload retrieval from public or attacker-controlled infrastructure. In Konni-linked cases, AutoIt scripts were used to deploy RemcosRAT alongside EndRAT and RftRAT. In one March 2026 campaign, a four-stage chain used obfuscated JavaScript, PowerShell decryption, a .NET loader named DEV.dll, and process hollowing into Aspnet_compiler.exe. Another 2026 campaign used HTA/VBScript, PowerShell, obfuscated JavaScript, reflective .NET loading, and process hollowing into Msbuild.exe.
Capabilities directly described in the content include full remote access, keylogging, screenshot capture, audio recording, camera access, credential theft, and surveillance. Specific configurations mention storage of keylogs in logs.dat, screenshot capture every 10 seconds, audio recording in 5-second clips, screenshot directories named Screenshots, audio directories named MicRecords, install names such as remcos.exe, and registry persistence under HKCU\Software\Remcos. RemcosRAT configuration is described as being stored in the PE RCData/SETTINGS resource and encrypted with RC4; extracted fields include C2 address, port, mutex, install filename, and keylogging log filename. The malware is also cited as an example in AES-related malware analysis due to state-array initialization patterns.
Persistence and execution techniques mentioned include scheduled tasks, startup-folder entries, registry Run/RunOnce-style persistence, process hollowing, and DLL sideloading. In Shadow Vector, RemcosRAT delivery involved side-loading through CiscoSparkLauncher.dll to trigger a malicious VERSION.dll, followed by installation of vulnerable WiseCleaner and Zemana drivers for privilege escalation and process-killing logic targeting security products. In Konni-related forensic findings, artifacts included C:\ProgramData\remcos\logs.dat and an AutoIt script sqlite4.au3 identified as RemcosRAT.
The content provides multiple infrastructure and configuration indicators tied to RemcosRAT campaigns. These include C2 or related endpoints such as 178.16.54[.]208 in a Konni campaign; the-new-age.co.ua:443, biches-yeah.co.ua:443, 178.33.57.149:443, 178.33.57.159:8899, and 88.151.192.14:443 in CERT-UA reporting; 216.250.249.222 on ports 80 and 443 in a March 2026 process-hollowing campaign; and goodpeopleswhitbrigheartwinthisindustryi.duckdns.org:14646 in the SkyLNK campaign. Reported mutexes include Rmc-3UG3BG and Rmc-E3G25N. One campaign used botnet name RemoteHost; another used botnet ID SkyLNK. A reported license hash was 72214B9FB81C38C5D9F33A771B74F635.
Targeting described in the content spans government, healthcare, technology, and manufacturing sectors worldwide, Ukrainian military and defense personnel, South Korean and North Korea-related targets in Konni campaigns, Colombian users and organizations via judicial/government impersonation, and broader financially motivated malware distribution operations. RemcosRAT also appears repeatedly as a payload delivered by malware-as-a-service or pay-per-install ecosystems including Amadey, GoLoader, and shared JavaScript/AutoIt wrapper campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis of the three identified AutoIt scripts revealed different RAT families, including EndRAT, RftRAT, and RemcosRAT.
The files distributed were malicious AutoIt scripts and modules that enable remote access and keylogging, as well as various RATs, including LilithRAT and RemcosRAT.
Red Akodon targets users... using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT, and XWorm.
"...and remote access trojans such as RemcosRAT in attacks targeting Ukraine."
"...to attack Russian organizations... with malware like RemcosRAT and DarkTrack RAT..."
32 distinct techniques documented for this family, organized by ATT&CK tactic.
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Process Injection T1055 VirtualAlloc RWX + DllCallAddress shellcode execution
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
LNK 내부에 숨겨 둔 데이터 블록(0x1D79FB)을 XOR(0x3D) 복호화 ... SUB 연산 기반의 반복키 문자열 난독화 ... RC4 알고리즘으로 암호화된 설정 데이터
6ca7a458985350ac082a9c9820d7f8d39128a4c4bda2f5d32f169a45b7b22bc6 MobaXterm_v26.1.exe ... 6ae334ce60d1a9b7fb96d1d0d0eda5ec7c2c31d3f0cf3e4d7e3056504d50043d WebEx_Client.exe ... 1a01ad25712d306f27f526332fdccf959f2de53207b54e4e80f60faa804d6cb6 FaceitInstaller_x64.exe ... f4491736743a16f1278b8ba01649ee93343764e35ae5e1c0d5e0c0e1d7e32c14 Zoom Installer
MITRE ATT&CK Mapping Tactic Technique ID Implementation Defense Evasion Process Injection T1055 VirtualAlloc RWX + DllCallAddress shellcode execution
After gaining unauthorized access to the victim’s KakaoTalk PC application, the threat actor selectively chose contacts from the friend list for secondary distribution of the malicious file.
The actor then remained concealed on the infected system for an extended period while collecting internal documents, user account information, and system environment data.
https://eorthopaedics.com/feed/note ... https://web-devtools.com/starlandfox ... https://sastoro.com/alpha/nrpilqjnut/ ... https://windowscreenrepairnearme.com/command
The RAT -- compiled February 3, 2026 -- phones home to a dedicated C2 at 216.250.249.222 on ports 80 and 443 using Remcos proprietary protocol (not HTTP, not TLS -- raw TCP masquerading on web ports).
외부 C2 서버에서 두 개의 파일을 내려받습니다 ... 첫 번째는 AutoIt3.exe ... 두 번째는 APDNHFU.pdf
122 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan family included in the classifier’s malware classes.
A remote access trojan mentioned as one of the payloads delivered by PhantomVAI in other campaigns.
A commercial remote access trojan abused in cybercrime campaigns. In this campaign it is delivered through a four-stage chain, process-hollowed into Aspnet_compiler.exe, and used for surveillance and remote control including keylogging, camera access, audio recording, screenshots, file management, command execution, and watchdog behavior.
A remote access trojan observed among the malware families delivered by the same AutoIt crypter operation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.