Remcos RAT Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
January 19, 2026
Last Seen
April 2, 2026

Remcos RAT is a commercially available remote access Trojan that threat actors deploy to gain covert control of infected Windows machines and exfiltrate data.

Overview

Remcos RAT is a commercially available remote access Trojan that threat actors deploy to gain covert control of infected Windows machines and exfiltrate data. In this campaign, attackers deliver Remcos via trojanized VeraCrypt installers to steal credentials, leveraging trusted software as an infection vector. The campaign underscores Remcos’ role as a credential-stealing, remote-access tool and its ongoing significance in cybersecurity operations.

Related Threat Clusters

Recent Intelligence Reports

  • Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries — Cybersecuritynews · April 2, 2026
  • Remcos RAT Campaign Uses Trojanized VeraCrypt Installers to Steal Credentials — Gbhackers · January 19, 2026

CVSS v3.1 Breakdown