Skip to content

Microsoft Security Intelligence: Backdoor:Win32/Remcos (updated 25 September 2023)

www.microsoft.com • October 9, 2026

We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn Microsoft threat actor names

Aliases: No associated aliases

Remcos is used to take control of an infected system and collect system information like keystrokes, webcam images, screen captures, and passwords.

Remcos supports many control commands to perform various tasks on a victim’s device.

Based on command-and-control (C2) commands, it can do further malicious activities such as start and stop keyloggers, download file, delete file, upload file, open and close camera, record audio, display warning message, and get clipboard data.

Read the following blogs for more information:

Flax Typhoon using legitimate software to quietly access Taiwanese organizations

How the Microsoft Incident Response team helps customers remediate threats

Threat actors strive to cause Tax Day headaches

Microsoft Defender Antivirus automatically removes threats as they are detected. However, many infections can leave remnant files and system changes. Updating your antimalware definitions and running a full scan might help address these remnant artifacts.

Users should keep their antivirus products up to date and do regular system scans to remove possible threats.

You can also visit our advanced troubleshooting page or the Microsoft virus and malware community for more help.

The backdoor drops a script file in a temp folder and initiates it to set it to sleep for some time then makes a copy of itself in continuous folders:

It also creates a Registry Key under the current user software.

The copy of the sample connects to defenderav.con-ip[.]com through the TCP port.

It creates a mutex ( Remcos-YTPKR ) and performs other keylogger activities. Sample used in this analysis

This backdoor has multiple variants that exhibit different behaviors. This analysis is based on the following sample:

69b94f987d06e3c69a8ee476ed16723fa8b13672b44c286b572cb7f09cdd7a4f (SHA-256)

Avoid opening files unless you’re confident they come from a legitimate source. Run periodic diagnostic scans with Microsoft Defender.

Keep your operating system and antivirus products up to date.

Take these steps to help prevent malware infection on your computer .

Following the mitigation steps below can help prevent malware attacks:

Keep backups so you can recover data affected by ransomware and destructive attacks. Use controlled folder access to prevent unauthorized applications from modifying protected files.

Harden internet-facing assets and ensure they have the latest security updates. Use threat and vulnerability management to audit these assets regularly for vulnerabilities, misconfigurations, and suspicious activity.

Turn on cloud-delivered protection and automatic sample submission on Microsoft Defender Antivirus. These capabilities use artificial intelligence and machine learning to quickly identify and stop new and unknown threats.

Turn on attack surface reduction rules , including rules that block credential theft, ransomware activity, and suspicious use of PsExec and WMI. To address malicious activity initiated through weaponized Office documents, use rules that block advanced macro activity, executable content, process creation, and process injection initiated by Office applications. To assess the impact of these rules, deploy them in audit mode.

Use the Microsoft Defender Firewall and your network firewall to prevent RPC and SMB communication among endpoints whenever possible. This limits lateral movement as well as other attack activities.

Turn on tamper protection features to prevent attackers from stopping security services.

You might observe the following symptoms on devices affected by this ransomware:

Created mutex: Remcos-YTPKR

Created Registry Key: HKEY_CURRENT_USER\SOFTWARE\Remcos-YTPKR1