RemcosRAT is a commercial Windows remote access trojan used in both cybercrime and espionage operations. It provides operators with persistent remote control of infected systems and is widely observed in phishing-led intrusions, loader-based delivery chains, and multi-stage malware campaigns. Documented capabilities include remote command execution, file transfer, screenshot capture, keylogging, audio or webcam surveillance in some campaigns, victim information collection, and theft or removal of browser-stored data. RemcosRAT configurations are commonly stored in encrypted resources and campaigns have used additional obfuscation, in-memory execution, process hollowing, pipe-based execution chains, and AutoIt-based launchers to evade detection.
The malware is frequently delivered through malicious shortcut files, HTA and JavaScript droppers, HTML smuggling, ISO or IMG container files, CAB archives, MSI installers, and loader families such as GuLoader and GoLoader. Observed execution chains include mshta- and PowerShell-based staging, DLL sideloading with signed binaries, and reflective or hollowed execution into legitimate Windows processes. Persistence mechanisms seen in the wild include Startup-folder shortcuts, scheduled tasks, copied payloads in user profile locations, and registry-based autoruns.
RemcosRAT has been associated with a broad range of threat activity, from commodity malware distribution to targeted state-linked operations. Reported users include UAC-0050 in espionage activity against Ukrainian government entities, UAC-0184 in campaigns targeting Ukrainian defense-related personnel, and Konni-linked operations targeting individuals in South Korea. It has also appeared in financially motivated distribution ecosystems such as Amadey and GoLoader campaigns, alongside other stealers, loaders, and RATs. Targeting has included government, defense-related users, banking victims, and general enterprise or consumer Windows users depending on the operator and delivery chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s weapon of choice is RemcosRAT, a notorious malware for remote surveillance and control... Analysis revealed UAC-0050's deployment of RemcosRAT in a targeted cyber intelligence operation against Ukrainian government agencies.
During 2019-2021 I was focused on analyzing campaigns orchestrated by the APT-C-36 group and RATs used by this same group and other cybercriminal groups such as RemcosRAT, AsyncRAT, Imminent Monitor RAT, etc.
The threat actor used an AutoIt script to launch RemcosRAT (Remote Access Trojan). On some victims’ systems, RemcosRAT 7.0.4 Pro was identified, indicating that the attackers were actively using the latest malware and tactics.
The files distributed were malicious AutoIt scripts and modules that enable remote access and keylogging, as well as various RATs, including LilithRAT and RemcosRAT.
Red Akodon targets users... using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT, and XWorm.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Inside there is a Visual Basic Script (VBS) file... Then PowerShell is executed and passing an encoded command.
Following the successful deobfuscation of the VBScript, we obtained a PowerShell script... It uses the | powershell - syntax to execute the decrypted payload as a new PowerShell process.
Upon launching, word_update.exe executes cmd.exe and shares malicious data through a pipe.
Inside there is a Visual Basic Script (VBS) file called Fiche de candidature .vbs which is executed when double-clicked.
Threat actors often resort to techniques such as process injection or hollowing to execute malicious code within authentic processes. However, employing a clever strategy, attackers leverage pipes to effectively bypass detection... the data was transmitted from word_update.exe to cmd.exe... After that launch explorer and moved malicious data in that memory.
Towards the end of the .lnk file, the threat actor has obfuscated the URL string... the 6.hta file... contains a VBScript file with fully obfuscated script content.
the threat actor attempted to deliver malware using HTML smuggling, a technique for sneaking malicious email attachments past gateway security controls.
6ca7a458985350ac082a9c9820d7f8d39128a4c4bda2f5d32f169a45b7b22bc6 MobaXterm_v26.1.exe ... 6ae334ce60d1a9b7fb96d1d0d0eda5ec7c2c31d3f0cf3e4d7e3056504d50043d WebEx_Client.exe ... 1a01ad25712d306f27f526332fdccf959f2de53207b54e4e80f60faa804d6cb6 FaceitInstaller_x64.exe ... f4491736743a16f1278b8ba01649ee93343764e35ae5e1c0d5e0c0e1d7e32c14 Zoom Installer
Threat actors often resort to techniques such as process injection or hollowing to execute malicious code within authentic processes. However, employing a clever strategy, attackers leverage pipes to effectively bypass detection... the data was transmitted from word_update.exe to cmd.exe... After that launch explorer and moved malicious data in that memory.
Its capabilities include running remote commands, downloading and uploading files, taking screenshots, recording keystrokes and recording the user’s webcam and microphone.
214 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan family included in the classifier’s malware classes.
Remote access trojan referenced among malware samples, associated here with IMG and CAB formats.
A remote access trojan mentioned as one of the payloads delivered by PhantomVAI in other campaigns.
A remote access trojan delivered by the same JavaScript wrapper technique in the broader campaign wave.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.