Skip to content
ThreatCluster

Remcos Backdoor Exploits Systems for Surveillance and Data Theft

First seen 9 Oct 2026, 11:33 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 12:39 UTC
  • •Remcos is a backdoor that enables remote control and surveillance of infected systems.
  • •The malware can capture keystrokes, webcam images, and clipboard data.
  • •Users are advised to update antivirus definitions and perform full system scans.

Remcos, a closed-source remote control tool, has been identified as a backdoor used to take control of infected systems, allowing attackers to collect sensitive information such as keystrokes, webcam images, and passwords. The malware supports a variety of commands for malicious activities, including keylogging, file manipulation, and audio recording. Microsoft has updated its threat intelligence to include Remcos, highlighting its capabilities in executing remote commands and conducting surveillance. Users are advised to keep their antivirus software up to date to mitigate risks associated with this malware. The tool has been linked to various malware campaigns, and its use of dynamic DNS for command-and-control communications raises concerns about its persistence and evasion tactics. Current reports do not indicate any in the wild, but the tool remains a significant threat due to its extensive functionality.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-09
Remcos identified as backdoor
Microsoft Security Intelligence reported Remcos as a backdoor used for system control and data theft.
Microsoft
2026-10-09
MITRE ATT&CK page updated
MITRE updated its page on Remcos, detailing its capabilities and usage in malware campaigns.
MITRE

More articles in this cluster (2)

Following this threat?

Track Apt-c-36 and Remcos in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected by Remcos?
Remcos can affect any Windows-based system where it is installed, as it operates through remote control capabilities.
Is there active exploitation of Remcos currently?
No active exploitation has been confirmed in the wild, but it remains a significant threat due to its capabilities.
What should organizations do to protect against Remcos?
Organizations should ensure their antivirus software is updated and conduct regular system scans to detect and remove potential threats.