Remcos (Remote Control & Surveillance) is a Windows remote access trojan used for espionage, data theft, and persistent unauthorized access. It provides remote command execution, file downloading and execution, file manipulation, keylogging, clipboard monitoring, screenshot capture, audio recording, and webcam capture. Additional capabilities include credential and browser-session collection, system and user discovery, and transmission of collected information to command-and-control infrastructure.
Remcos is commonly distributed through phishing and malicious spam using business-themed documents, compressed attachments, disguised executables, and malicious download links. Delivery campaigns have exploited Microsoft Office vulnerabilities CVE-2017-0199 and CVE-2017-11882, as well as WinRAR vulnerability CVE-2023-38831. Multistage chains employ VBScript, PowerShell, AutoIt crypters, obfuscated or encrypted payloads, and image-embedded data. Remcos has also been distributed as a purported recovery hotfix following the July 2024 CrowdStrike outage.
Remcos supports hiding through injection into another process, and delivery chains have executed its payload inside legitimate Windows processes using memory-resident loading. Observed campaigns establish persistence through registry autorun entries or Startup-folder shortcuts. Its configuration is stored in an RC4-encrypted resource, and a mutex prevents concurrent instances. Remcos-associated samples and loaders employ sandbox, virtual-machine, and debugger checks; campaigns have also used User Account Control bypass techniques.
Threat actors deploying Remcos include Gorgon Group, TA558, and OPERA1ER. Documented targeting includes government organizations, banks, manufacturing enterprises, and hospitality businesses. Campaigns have affected organizations across multiple regions, including government targets in Ukraine and manufacturing, government, and banking organizations in Russia and Belarus. Remcos is a shared commodity tool rather than a malware family exclusive to one actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-38831, the WinRAR zero-day remote code execution vulnerability, has been exploited in the wild to distribute several malware families.
CVE-2017-0199 is still targeted to allow for execution of remote code from within an XLS file. The campaigns delivered a malicious XLS file with a link from which a remote HTA or RTF file would be executed to download the final payload.
The RTF document has embedded malicious code. It Leverages the Equation Editor Vulnerability (CVE-2017-11882) to trigger the download of the subsequent payloads in the attack chain. The process utilizes the legitimate executable “EQNEDT32.EXE” to initiate the execution of malicious shellcode.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
At the beginning of 2022, SophosLabs and Sophos MTR had been investigating an uptick in reports of attacks against Microsoft SQL Server installations, using two venerable and long-patched remote code execution vulnerabilities (CVE-2019-1068, CVE-2020-0618). | These attacks leverage Remcos (a commercially available remote access trojan) and deploy various families of ransomware including TargetCompany, aka Mallox; GlobeImposter, aka Alpha865qqz; and BlueSky.
And sure enough, the MD5 of the file {CACAF1F7-CE7C-4CA2-B9E3-ABBC9F6E965D}.exe maps to a file on VirusTotal named Erlianaw.exe, the filename we saw earlier during the analysis of the LNK file. Figure 5: Erlianaw.exe - Remcos on VirusTotal
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
46 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysis of the downloaded file revealed previously undocumented techniques used in the delivery chain for the Remcos implant.
Analysis of the downloaded file revealed previously undocumented techniques used in the delivery chain for the Remcos implant.
Analysis of the downloaded file revealed previously undocumented techniques used in the delivery chain for the Remcos implant.
Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.
The Remcos (Remote Control & Surveillance) RAT malware provides attackers with complete control over an infected system. It can be used for data theft, espionage, and other malicious activities.
В результате чего осуществляется создание процесса Regasm.exe, посредством которого происходит заражение устройства трояном Remcos.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
Upon exploiting the successful vulnerability, it leads to BAT file execution, which pretends to be a PDF file.
TA558 использовала команды Windows PowerShell для загрузки данных, обфускации полезной нагрузки и запуска ВПО
TA558 использовали скрипты Visual Basic для запуска ВПО и эксплуатации CVE
The downloaded content undergoes a decoding process involving both reversal and Base64 decoding.
полезная нагрузка размещалась в изображениях и закодированных текстовых файлах
This payload is then injected into the legitimate “RegAsm.exe” process.
This assembly is a variant of Remcos RAT, which is then injected into the legitimate Windows process ‘RegAsm’ ... for execution.
TA558 использовало команды позволяющее декодировать полезную нагрузку полученную в ходе атаки из изображений и файлов
MSHTA acting as VBScript interpreter ['DefenseEvasion', 'Execution'] ['T1218.005', 'T1059.005']
Application Windows Discovery (T1010) — Remcos ... осуществляло сбор информации о приложениях установленных в системе
Remcos позволяющее осуществлять поиск файлов в системе, а также имеет возможности файлового менеджера
The Remcos RAT grants threat actors’ extensive control, enabling activities such as remote control, keylogging, data theft, screenshot capture, file manipulation, and command execution.
This file records all activities, including keystrokes and data copied to the clipboard.
Remcos которое могло осуществлять снятие информации с аудиовыходов зараженного устройства
1,767 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A commodity remote-access trojan delivered via SVG-borne malware-delivery campaigns targeting Latin America, particularly Colombia.
Remcos RAT is the final payload delivered through a phishing XLS attachment exploiting CVE-2017-0199. It provides remote command execution and collects system and user data through keylogging, screen capture, and file manipulation, transmitting collected information and command results to its C2 server.
A remote-access trojan delivered through phishing emails carrying a RAR archive and obfuscated VBScript/PowerShell stages. It receives and executes remote commands, collects system and user information, performs keylogging, captures screenshots, manipulates files, and exfiltrates collected data and command results to its C2 server.
A password-stealing malware family distributed via Italian malspam campaigns during the reporting period.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.