Ukrainian government entities were targeted in a cyber-espionage campaign attributed to UAC-0050 that deployed Remcos RAT through a malicious .lnk file and a multi-stage chain using mshta.exe, obfuscated VBScript, and PowerShell. Researchers said the malware downloaded a decoy document themed around consultancy and Israel Defense Forces training, then established persistence in AppData before using unnamed Windows pipes to move decrypted payload data into cmd.exe memory, a technique designed to evade EDR and antivirus tools. The analyzed Remcos 4.9.2 Pro sample was configured to contact 194.87.31.229:6438 under the botnet name RemoteHost and was observed collecting victim data, altering registry settings, and removing browser data.
The operation fits a broader pattern of Remcos use across phishing and espionage campaigns, where attackers repeatedly rely on lures such as invoices, war-related themes, password-protected documents, and malicious archives to deliver the RAT. Prior reporting has documented Remcos infections using Office exploits, macros, PowerShell loaders, UAC-bypass techniques, process injection, and fileless or in-memory execution, while later tracking of UAC-0050 linked the cluster to continued operations against Ukraine using shifting malware families and suspicious hosting infrastructure. The campaign underscores how a commercially available RAT continues to be adapted by both criminal and state-aligned operators for stealthy access, surveillance, and follow-on intrusion activity.

See the actors and campaigns active against you right now.
32 events from the most recent confirmed update back to the earliest known activity.
On February 5, 2025, Intrinsec says UAC-0050 launched another NetSupport Manager campaign. The payload was downloaded from cansupeker.com and communicated with 5.181.159.47/fakeurl.htm.
On January 14, 2025, UAC-0050 launched a phishing campaign delivering NetSupport Manager via a JS downloader hosted on 4sync. Intrinsec says the campaign downloaded an archive from 45.155.249.215 and used C2 at 185.157.213.71/fakeurl.htm.
Malpedia notes that Microsoft Threat Intelligence reported in 2025 that tax-themed phishing campaigns associated with Storm-0249 deployed malware including Remcos.
Malpedia notes that Cisco Talos reported in 2025 that Gamaredon abused LNK files to distribute the Remcos backdoor.
Intrinsec reports that a second January 2025 UAC-0050 campaign spoofed Raiffeisen Bank's Ukrainian subsidiary and delivered NetSupport Manager from 147.45.44.200 with C2 at 147.45.44.255.
On December 25, 2024, Intrinsec says UAC-0050 used IP 109.71.247.168 in a phishing campaign impersonating Nova Pochta. The chain used a Dropbox-hosted archive sequence ending in an executable that deployed a LiteManager MSI communicating with 101.99.91.150:5651.
On December 13, 2024, another threatening email impersonated Pavel Vrublevsky and threatened attacks in Switzerland, Poland, Berlin, and Ukraine.
Also on December 12, 2024, another threatening email in Polish, English, and Dutch claimed intent to assassinate French President Emmanuel Macron during his visit to Warsaw.
On December 12, 2024, bomb-threat emails tied by Intrinsec to a UAC-0050-linked PsyOps branch were sent from IP 213.176.74.191. The messages targeted Ukrainian entities and allies and referenced Rutor and Telegram channels associated with a Russian arms-seller persona.
On November 12, 2024, Intrinsec reports that a UAC-0050 phishing campaign targeted a wide range of entities, mostly in Ukraine, and delivered a Remcos payload. The malware communicated with 111.90.140.65:2404 using botnet ID "hstnw" and also downloaded additional unidentified malware.
On October 31, 2024, Intrinsec says UAC-0050 used Russian IP 109.71.247.168 in a phishing campaign spoofing the Office of the Security Service of Ukraine. The lure chain delivered sLoad through nested archives and an LNK file that fetched a VBS script and decoy icon.
Elastic's analysis includes a screenshot naming example timestamped March 8, 2024, while describing detection opportunities for Remcos 4.9.3 such as Run key persistence, process injection, UAC bypass, browser data deletion, keylogging, screenshots, and audio capture.
Malpedia notes that Fortinet reported in 2024 that a new campaign used Remcos RAT to exploit victims. The source content does not provide a more precise date.
Malpedia notes that Positive Technologies reported in 2024 that the TA558 SteganoAmor campaign mass-attacked companies and public institutions worldwide using malware including Remcos.
Uptycs said its platform alerted on a suspicious .lnk file on December 21, 2023, prompting investigation of a cyber-espionage campaign targeting Ukrainian government entities. The campaign was attributed to UAC-0050 and used RemcosRAT with a pipe-based execution chain.
Malpedia states that CERT-UA reported in 2023 that UAC-0050 used RemcosRAT and Meduza Stealer in a mass cyberattack against Ukraine and Poland.
Malpedia notes that SOC Prime reported in 2023 that UAC-0050 and UAC-0096 spread Remcos spyware via phishing attacks.
Malpedia states that CERT-UA reported in 2023 that UAC-0050 conducted cyberattacks against Ukrainian state bodies using Remcos.
Bitdefender tracked two phishing campaigns starting on March 1, 2022, exploiting Russia's invasion of Ukraine as a lure. One of them impersonated a South Korean healthcare company and used a malicious Excel file exploiting CVE-2017-11882 to install Remcos.
In late February 2022, AhnLab ASEC reported a phishing campaign using a "Tax.gz" attachment to deliver Remcos RAT. The chain used different payloads by system architecture and included a UAC-bypass technique abusing a fake "C:\Windows \System32" path, winsat.exe, and a malicious version.dll.
AhnLab said similar PowerShell scripts and related files tied to the tax-themed Remcos campaign were being distributed through multiple external URLs around February 24.
Malpedia also notes that in 2022 HP reported campaigns targeting the African banking sector with Remcos, and Intel 471 said PrivateLoader served as initial access for malware schemes including Remcos.
Malpedia notes that Trustwave reported in 2022 that attackers leveraged the Russia-Ukraine conflict in multiple spam campaigns involving Remcos.
Malpedia records multiple 2021 campaigns involving Remcos, including a fake SafeMoon app, Colombian and South American operations, U.S. taxpayer targeting, MSBuild-based fileless delivery, and widespread RAT campaigns spoofing government or health themes.
Malpedia notes that in 2020, Bitdefender reported coronavirus-themed malware activity including Remcos, Zscaler said Amadey pushed Remcos, and Proofpoint described packers hiding payloads including Remcos.
Malpedia cites several 2019 developments: Symantec linked Remcos to Elfin/APT33 targeting organizations in Saudi Arabia and the United States, while Check Point, Trend Micro, and Proofpoint reported phishing and downloader activity delivering Remcos.
On August 22, 2018, Cisco Talos published "Picking Apart Remcos Botnet-In-A-Box," analyzing Remcos as a botnet-enabled commodity RAT platform.
Malpedia notes that RiskIQ reported in 2018 on an espionage campaign using spear phishing and RATs including Remcos against Turkish defense contractors.
On February 14, 2017, Fortinet published analysis of a campaign distributing Remcos via spammed Office documents named Quotation.xls and Quotation.doc. The documents used obfuscated macros and attempted a UAC-bypass technique before executing Remcos v1.7.3 Pro.
Fortinet stated that Remcos v1.7.3 Pro had been released on January 23, 2017. The version later appeared in a spam-delivered malicious document campaign.
Malpedia's UAC-0050 reference notes that malspam campaigns used CVE-2017-0199 to distribute Remcos RAT in 2017. No more precise date is provided in the source content.
Fortinet reported that Remcos had been sold on hacking forums since the second half of 2016, establishing its availability before later campaigns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 100 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
12 references tracked. Mallory keeps watching after this page renders.
malpedia.caad.fkie.fraunhofer.de
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceblog.morphisec.com
Open sourceinfosecwriteups.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceblog.fortinet.com
Open sourceintrinsec.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.