A large-scale phishing campaign targeted German companies across multiple industries with spoofed emails impersonating legitimate local businesses and carrying archive attachments that hid executables disguised as PDF or document files. Check Point said the payload installed Remcos, a commercially available remote access trojan that can give attackers full control of infected systems while operating silently in the background.
Once executed, Remcos enabled capabilities including privilege escalation, persistence, process injection, keylogging, screen and audio capture, and password theft. The malware’s command-and-control infrastructure relied on Dynamic DNS services, including No-IP, aligning with MITRE ATT&CK technique T1311, a method that helps operators maintain flexible and evasive C2 endpoints as domains and IP addresses change.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Check Point researchers observed a large-scale phishing campaign in the first week of June 2019 targeting German companies across multiple industries. The emails spoofed legitimate German businesses and used archive attachments with executables disguised as documents to install the Remcos remote access trojan.
Check Point publicly reported the campaign and released technical details on the Remcos malware, its use of Dynamic DNS infrastructure, product detections, and indicators of compromise including file hashes and malicious domains. The report identified domains such as ablegod.hopto[.]org and other DDNS-based infrastructure tied to the operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.