RemCom is an open-source remote command execution utility for Windows that serves as a PsExec-like replacement, allowing operators to execute processes on remote systems through service-based execution. It is best characterized as a legitimate dual-use administrative tool that is frequently repurposed by threat actors for lateral movement and post-compromise operations inside Windows environments. Observed malicious use includes remote execution of encoded PowerShell commands, deployment of additional payloads, and propagation across compromised enterprise networks.
RemCom has appeared in intrusion activity associated with multiple threat actors and operations, including APT39, Mango Sandstorm (formerly tracked by Microsoft as MERCURY), Stately Taurus, and reporting on FANCY BEAR tradecraft. It has also been referenced in destructive and ransomware-related operations as an auxiliary tool used after initial compromise, including BlackCat/ALPHV-linked activity and environments later impacted by IsaacWiper. In these contexts, RemCom is typically not the initial payload but a post-exploitation utility used to extend access, execute tooling remotely, and support movement between hosts.
Operationally, RemCom is commonly associated with creation of temporary or attacker-controlled Windows services to launch commands on remote hosts, making it relevant to service-execution and remote-service-creation detections. Because it is openly available and can be used legitimately by administrators, detections require contextual analysis to distinguish benign administration from adversary tradecraft. Its repeated use across espionage, ransomware, and destructive campaigns has made RemCom a well-known indicator of hands-on-keyboard lateral movement in Windows enterprise intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Remote services (leveraging RemCom tool) to run encoded PowerShell commands within organizations.
APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Consistent with GRU techniques and 'methods of persistence' identified by computer forensic investigators in other intrusions, the hackers again used X-Agent to log keystrokes, take screenshots, and gather system data; used a lateral-movement tool called RemCom; and used Mimikatz, a credential-harvesting tool.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote administration/offensive tool incorporated into newer BlackCat variants to help propagate through compromised networks.
An open-source alternative to PsExec used for lateral movement and remote command execution on Windows systems.
RemCom is a remote shell tool used for executing processes on remote Windows systems, facilitating lateral movement and remote command execution.
Remote execution utility used to launch commands on other systems for lateral movement and post-compromise operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.