RemcosRAT is a commercial Windows remote access tool widely abused as a remote access trojan for surveillance, information theft, and control of compromised systems. It supports command execution, file transfers, screenshot capture, keystroke logging, and recording from webcams and microphones. Malicious deployments have enabled credential theft and collection of victim information, including computer names and usernames. Analyzed payloads store RC4-encrypted configuration data in embedded resources, defining command-and-control settings, installation options, and surveillance features.
RemcosRAT is distributed through spearphishing, malicious attachments, and social-engineering messages, including messages sent through compromised messenger accounts. Observed lures impersonate judicial institutions, recruiters, tax authorities, and trusted acquaintances. Delivery chains have used HTML smuggling, disk images, password-protected archives, malicious shortcuts, HTA files, and staged JavaScript, PowerShell, and AutoIt execution. GuLoader, GoLoader, and Amadey have delivered RemcosRAT as a downstream payload.
Deployment chains employ DLL sideloading, process hollowing, in-memory execution, obfuscation, and analysis-environment checks to conceal execution. Observed installations maintain persistence through scheduled tasks and startup entries. In the Shadow Vector campaign, the RemcosRAT loader attempted to terminate security-product processes and deployed vulnerable WiseCleaner and Zemana drivers associated with CVE-2023-1486 and CVE-2022-42045 for kernel-level privilege escalation. These techniques belong to particular delivery chains rather than necessarily to the core RAT.
RemcosRAT is used by both cybercriminal and espionage operators. UAC-0050 deployed it against Ukrainian government agencies, and UAC-0184 used it in operations targeting Ukraine’s Defense Forces. Konni campaigns deployed it against South Korean targets connected to North Korean human-rights and defector communities. Other observed targeting includes individuals and organizations in Colombia and an employee of a West African bank.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Diagram of a multistage attack delivering RemcosRAT through phishing and DLL side-loading, followed by driver-based privilege escalation using vulnerable kernel-mode drivers like Zemana (CVE-2022-42045) and WiseCleaner (CVE-2023-1486). | The executable side loads the legitimate ‘CiscoSparkLauncher.dll’, which in turn triggers the malicious DLL to decode and deploy three files to the ‘%Temp%’ directory: two vulnerable drivers used for kernel-level privilege escalation, and the final RemcosRAT payload.
Diagram of a multistage attack delivering RemcosRAT through phishing and DLL side-loading, followed by driver-based privilege escalation using vulnerable kernel-mode drivers like Zemana (CVE-2022-42045) and WiseCleaner (CVE-2023-1486). | The executable side loads the legitimate ‘CiscoSparkLauncher.dll’, which in turn triggers the malicious DLL to decode and deploy three files to the ‘%Temp%’ directory: two vulnerable drivers used for kernel-level privilege escalation, and the final RemcosRAT payload.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group’s weapon of choice is RemcosRAT, a notorious malware for remote surveillance and control... Analysis revealed UAC-0050's deployment of RemcosRAT in a targeted cyber intelligence operation against Ukrainian government agencies.
During 2019-2021 I was focused on analyzing campaigns orchestrated by the APT-C-36 group and RATs used by this same group and other cybercriminal groups such as RemcosRAT, AsyncRAT, Imminent Monitor RAT, etc.
The threat actor used an AutoIt script to launch RemcosRAT (Remote Access Trojan). On some victims’ systems, RemcosRAT 7.0.4 Pro was identified, indicating that the attackers were actively using the latest malware and tactics.
The files distributed were malicious AutoIt scripts and modules that enable remote access and keylogging, as well as various RATs, including LilithRAT and RemcosRAT.
Red Akodon targets users... using remote access trojans (RAT) like RemcosRAT, QasarRat, AsyncRAT, and XWorm.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
eSentire has observed a substantial increase in malware being delivered through tax-themed phishing emails. Cybercriminals are exploiting the urgency and importance of tax-related communications to trick individuals into opening malicious email links, leading to malware infections.
Inside there is a Visual Basic Script (VBS) file... Then PowerShell is executed and passing an encoded command.
Following the successful deobfuscation of the VBScript, we obtained a PowerShell script... It uses the | powershell - syntax to execute the decrypted payload as a new PowerShell process.
Upon launching, word_update.exe executes cmd.exe and shares malicious data through a pipe.
Inside there is a Visual Basic Script (VBS) file called Fiche de candidature .vbs which is executed when double-clicked.
Towards the end of the .lnk file, the threat actor has obfuscated the URL string... the 6.hta file... contains a VBScript file with fully obfuscated script content.
the threat actor attempted to deliver malware using HTML smuggling, a technique for sneaking malicious email attachments past gateway security controls.
6ca7a458985350ac082a9c9820d7f8d39128a4c4bda2f5d32f169a45b7b22bc6 MobaXterm_v26.1.exe ... 6ae334ce60d1a9b7fb96d1d0d0eda5ec7c2c31d3f0cf3e4d7e3056504d50043d WebEx_Client.exe ... 1a01ad25712d306f27f526332fdccf959f2de53207b54e4e80f60faa804d6cb6 FaceitInstaller_x64.exe ... f4491736743a16f1278b8ba01649ee93343764e35ae5e1c0d5e0c0e1d7e32c14 Zoom Installer
222 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan family included in the classifier’s malware classes.
Remote access trojan referenced among malware samples, associated here with IMG and CAB formats.
A remote access trojan mentioned as one of the payloads delivered by PhantomVAI in other campaigns.
A commercial remote access trojan abused in cybercrime campaigns. In this campaign it is delivered through a four-stage chain, process-hollowed into Aspnet_compiler.exe, and used for surveillance and remote control including keylogging, camera access, audio recording, screenshots, file management, command execution, and watchdog behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.