Remcos RAT is a commercially available remote access Trojan that threat actors deploy to gain covert control of infected Windows machines and exfiltrate data.
Remcos RAT is a commercially available remote access Trojan that threat actors deploy to gain covert control of infected Windows machines and exfiltrate data. In this campaign, attackers deliver Remcos via trojanized VeraCrypt installers to steal credentials, leveraging trusted software as an infection vector. The campaign underscores Remcos’ role as a credential-stealing, remote-access tool and its ongoing significance in cybersecurity operations.
A new Remcos RAT campaign has been identified, employing obfuscated scripts and trusted Windows binaries to execute a largely fileless infection chain. The attack initiates through a phishing email containing a ZIP…
A malware campaign has been identified that distributes the Remcos RAT disguised as VeraCrypt installers. This attack primarily targets South Korean users, particularly those involved with illegal online gambling, but…