Skip to content
Phishing Campaign Uses Weaponized Shipping Documents to Distribute Remcos RAT

Phishing Campaign Uses Weaponized Shipping Documents to Distribute Remcos RAT

First seen 22 Jan 2026, 02:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A phishing campaign is exploiting fake shipping emails to deliver Remcos RAT, a remote access trojan. Victims are tricked into opening malicious Word documents disguised as legitimate shipping documentation, leading to unauthorized access and control over their systems. The campaign impersonates Vietnamese shipping companies to enhance its credibility.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Remcos in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed