Remcos RAT is a Windows remote access trojan originally developed as a commercial remote administration tool and later widely abused by criminal and espionage operators. It provides persistent remote control of infected systems and supports surveillance, credential and information theft, and operator tasking through command-and-control infrastructure. Documented functionality includes remote command execution, collection of system and user information, keylogging, screen capture, clipboard monitoring, file manipulation, registry modification, browser and Windows credential theft, webcam and microphone access, and exfiltration of collected data. Some variants dynamically decrypt APIs and configuration data at runtime, load additional modules on demand, and stream stolen data directly to operators, improving stealth and reducing reliance on local staging artifacts. Remcos also supports persistence and cleanup behaviors, including use of autorun mechanisms and removal of traces after execution.
Observed delivery chains show Remcos commonly distributed through phishing and malspam, often using business-themed lures and malicious attachments. Reported infection sequences include exploitation of Microsoft Office vulnerability CVE-2017-0199, obfuscated JavaScript, CMD, PowerShell, HTA, and .NET loader stages, steganographic payload concealment, fileless in-memory execution, and abuse of legitimate Windows or Microsoft-signed binaries for proxy execution. Remcos has also been delivered through DLL sideloading and through broader malware distribution ecosystems involving loaders and staged payload retrieval.
Remcos appears across both cybercrime and espionage activity. It has been observed in commodity malware campaigns alongside stealers and other RATs, and in targeted intrusions against Pakistani law enforcement organizations where activity was linked to a suspected India-nexus actor overlapping with TAG-179 and the Mysterious Elephant / APT-C-08 ecosystem. Targeting associated with these intrusions included police and citizen-data systems containing biometric, criminal, personnel, and complaint information. Remcos is also regularly seen in financially motivated phishing operations and multi-payload delivery chains. Its combination of mature remote administration features, modular surveillance capability, and flexible staging methods has made it a durable and widely reused malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
However, the document contains the CVE-2017-0199 vulnerability, which exploits OLE objects. This vulnerability is a remote code execution (RCE) flaw that exploits the OLE2Link feature in Microsoft Office; when a user opens the document, it automatically accesses an external URL to download and execute additional Malicious Files (such as HTA files). | At this point, the loader operates by receiving the C2 server address—from which it will download the Remcos RAT—as an argument value. Ultimately, the Remcos RAT is malware that receives and executes remote commands on an infected system; it collects system and user information through various functions such as keylogging, screen capture, and file manipulation.
"...Colombian organizations were reported by Darktrace to have been targeted by Blind Eagle in an attack campaign involving the abuse of the Windows vulnerability, tracked as CVE-2024-43451, that has been ongoing since November."
...triggers an exploit for a years-old security flaw in Microsoft Office (CVE-2017-11882) to distribute a new variant of Remcos RAT...
Windows Office Product Spawned Uncommon Process ... CVE-2023-21716 Word RTF Heap Corruption, CVE-2023-36884 Office and Windows HTML RCE Vulnerability ...
Group-IB Threat Intelligence unit discovered a zero-day vulnerability, CVE-2023-38831, in WinRAR, a popular compression tool. Cybercriminals exploited this vulnerability to deliver various malware families, including DarkMe and GuLoader, by crafting ZIP archives with spoofed extensions. | The malware was distributed alongside other malware families, such as GuLoader and Remcos RAT, via malicious ZIP archives posted on popular trading forums or distributed via file-sharing services.
60 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
Four different threat clusters have been flagged, each deploying a unique malware family: PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. The use of Remcos RAT has been linked to an India-nexus threat actor.
We attribute the Remcos C2 server 89.31.121[.]220 to a suspected India-nexus threat actor, which Recorded Future tracks as TAG-179.
[👽TA] TA558 (🏴): Steganography using other malwares (AgentTesla, FormBook, Remcos, LokiBot, GuLoader or XWorm)
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The fake update prompt would have hit anyone using the site, including officers and ordinary citizens.
The China-nexus threat actor is also said to have compromised one of these web applications to deploy a custom implant masquerading as a portal update.
Socket has published research findings describing a Go module that posed as a DNS and subdomain scanner while acting as a first-stage Windows malware loader.
it uses the Win32_Process.Create() method of WMI to execute an obfuscated PowerShell script in the background
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
The module's main.go launches a hidden PowerShell command that downloads content from muckcoding.com.
it uses the Win32_Process.Create() method of WMI to execute an obfuscated PowerShell script in the background
the document contains the CVE-2017-0199 vulnerability, which exploits OLE objects. This vulnerability is a remote code execution (RCE) flaw that exploits the OLE2Link feature in Microsoft Office; when a user opens the document, it automatically accesses an external URL to download and execute additional Malicious Files
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
The payload chain modifies Microsoft Defender and UAC settings, establishes persistence through scheduled tasks and services...
Socket describes the decoded script as a multi-layer loader using Base64 encoding and XOR decryption.
The script downloads a steganographically embedded PNG file from an additional C2 server and then extracts a .NET loader-type malware—encoded in Base64—using the strings “IN-” and “-inl” as markers.
The researchers also found malicious files disguised as software updates planted directly on Balochistan Police’s public Complaint Management System.
It then decrypts this, loads it into memory, and executes it.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
it collects system and user information through various functions such as keylogging, screen capture, and file manipulation
The payload chain... communicates with Telegram or other public web services.
Rather than hardcoding a payload URL, the resolver retrieves text from public platforms, searches it for the marker string 'LastW,' then decrypts the trailing blob with a hardcoded key to recover the actual download location. Primary dead drops include Pastebin and a paste service called Rlim, with fallbacks across YouTube, Instagram, Telegram, Google Docs, and GitCode.
725 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
REMCOS10
A remote access trojan used in the observed espionage activity; the content explicitly associates its use with an India-nexus actor.
Remcos RAT was linked to an India-aligned intrusion set targeting Pakistani law enforcement, with infrastructure and tactical overlaps to Mysterious Elephant.
Remote access trojan-style malware detected among the campaign payload stages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.