Remcos RAT is a commercially sold Windows remote access trojan and remote administration tool that has been widely abused in cybercrime and espionage operations. It is commonly delivered through phishing and spearphishing campaigns, including business-themed lures, government impersonation, malicious archives, script-based droppers, trojanized documents, and multi-stage fileless loaders. Observed delivery chains have also included exploit-based document attacks, malicious links, compromised websites, and staged payload deployment by other malware families and crypter services.
On compromised Windows systems, Remcos provides full remote control and supports command execution, file management, screenshot capture, user activity monitoring, and deployment of additional payloads. Reported variants and campaigns have also used it for credential theft, keylogging, reconnaissance, registry modification, and broader post-compromise surveillance. In some intrusion sets it appears as a secondary payload after an initial loader or access tool establishes foothold and persistence.
Recent observed campaigns have used Remcos as a final payload in multi-stage infection chains employing in-memory execution, reflective loading, shellcode loaders, Lua- or AutoIt-based loaders, bitmap-embedded payload concealment, and anti-analysis measures such as API unhooking and breakpoint neutralization. Persistence mechanisms associated with campaigns delivering Remcos have included scheduled tasks, startup items, PowerShell launchers, and Run key execution, although these mechanisms may belong to the surrounding loader chain rather than Remcos itself.
Remcos has been used against a broad range of targets, including businesses, taxpayers, government entities, financial services, healthcare, hospitality, and law enforcement-related organizations. It has appeared in campaigns targeting Indian organizations with tax-themed lures, global phishing operations delivering commodity malware, malspam activity in Europe, and post-compromise activity linked to financially motivated actors. It has also been observed in intrusion clusters associated with suspected India-nexus activity targeting Pakistani law enforcement, and as an auxiliary payload in campaigns attributed to the Russian-speaking financially motivated cluster UAT-11795. Its prevalence across unrelated campaigns reflects its role as a versatile commodity RAT favored for remote control, surveillance, and theft of sensitive information.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Remcos ... It exploits CVE-2017-0199 (Microsoft Office OLE2Link) to deliver fileless payloads. | Remcos is a commercially sold remote administration tool... widely abused for espionage and credential theft. It exploits CVE-2017-0199...
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
...triggers an exploit for a years-old security flaw in Microsoft Office (CVE-2017-11882) to distribute a new variant of Remcos RAT...
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
Group-IB Threat Intelligence unit discovered a zero-day vulnerability, CVE-2023-38831, in WinRAR, a popular compression tool. Cybercriminals exploited this vulnerability to deliver various malware families, including DarkMe and GuLoader, by crafting ZIP archives with spoofed extensions. | The malware was distributed alongside other malware families, such as GuLoader and Remcos RAT, via malicious ZIP archives posted on popular trading forums or distributed via file-sharing services.
58 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A 64-bit path drops CastleStealer, while a 32-bit path drops Remcos RAT.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
The Remcos cluster points elsewhere. SentinelLABS links it to a suspected India-nexus actor that Recorded Future tracks as TAG-179.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign starts with a phishing email. Some carry a malicious ZIP or RAR archive. Others link out to one. The lures lean on trust and urgency. Attackers impersonate known brands and use payment or shipping themes.
Once connected, the trojan provides the attacker with total system control. It enables remote command execution and file management.
It can run shell commands, inject 32-bit or 64-bit shellcode, or download more files.
The attack chain is set in motion when a would-be victim executes an email attachment that comes in the form of a heavily obfuscated JavaScript that, when executed, establishes persistence on the victim's system and launches a second-stage loader.
Exploitation of CVE-2022-30190 (Follina/MSDT “Dogwalk”) for arbitrary code execution
Inside the archive sits an obfuscated JavaScript file. It hides in heavy junk code and uses control-flow flattening to defeat analysis.
Observed campaigns have targeted financial services (34%), healthcare (25%), and government (10%), with notable attacks impersonating the Indian Income Tax Department and the US Social Security Administration.
A reflective loader then maps it straight into memory, so little touches disk.
831 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan delivered via GST-themed phishing emails targeting Indian businesses. It is launched in memory after custom .NET loaders decrypt and load it, then provides total system control, including remote command execution, file management, keystroke logging, credential harvesting, screenshot capture, user activity monitoring, persistence via registry run keys and PowerShell, and the ability to deploy additional payloads.
Secondary payload dropped by Starland RAT on 32-bit systems, providing remote access capabilities.
Remote access trojan delivered as a final payload by the TTF Trap phishing campaign.
A remote-access trojan delivered as a payload by Cruciferra.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.