Remcos is a malware family tracked across 23 threat clusters and 30 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity July 21, 2026.
A Russian threat actor known as UAT-11795 has been deploying the Starland RAT and WLDR agent since June 2025, primarily targeting users in the U.S., Germany, Romania, and Venezuela. The group uses trojanized installers…
A recent cyber campaign utilizes a malicious ZIP archive containing a VHDX file to deliver the Remcos Remote Access Trojan (RAT). Upon mounting the VHDX, an obfuscated JavaScript file executes, triggering a series of…
Two phishing campaigns have been identified targeting organizations in Greece, Spain, Slovenia, Bosnia, Croatia, and several South American countries, aiming to deliver the Formbook infostealer malware. The first…
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, has been observed delivering multiple remote access trojans (RATs) including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2) through a social…
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
Since late March 2026, a large-scale phishing campaign has been observed utilizing disguised TrueType Font (.ttf) files to deliver Lua-based loaders and various malware, including Agent Tesla and Remcos. The attackers…
A phishing campaign has been detected that exploits Google Cloud Storage to deliver the Remcos remote access trojan (RAT). Attackers host a fake Google Drive login page on the legitimate domain storage.googleapis.com,…
Agentic LLM browsers, which automate user tasks by reading and interacting with web content, have introduced significant security risks related to prompt injection and data theft. These browsers, including Perplexity…
A phishing campaign is targeting users in India with a malicious attachment named 'GST Debit Note Apr_26.com.' This attachment is a multi-stage steganographic loader that delivers the Remcos RAT, enabling attackers to…