Remcos Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
30
occurrences
First Seen
November 18, 2025
Last Seen
July 21, 2026

Remcos is a malware family tracked across 23 threat clusters and 30 intelligence report mentions on ThreatCluster. First observed November 18, 2025; most recent activity July 21, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • The Ttf Trap A Global Campaign Of A Low Detection Lua Loader — www.fortinet.com · July 21, 2026
  • Unpacking “Cruciferra”: An Analysis of a Sophisticated Crypter Service — Proofpoint · July 20, 2026
  • Cruciferra Crypter Uses Process Ghosting to Evade Detection — Infosecurity-Magazine · July 20, 2026
  • Fake TTF files deliver stealthy malware in global phishing campaign — Csoonline · July 17, 2026
  • Phishing Campaign Hides Lua Loader as TrueType Font File — Infosecurity-Magazine · July 16, 2026
  • Russian hackers trojanize WebEx, Zoom apps to push Starland malware — Bleepingcomputer · July 16, 2026
  • Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi — Cybersecuritynews · June 22, 2026
  • Multi — Gbhackers · June 22, 2026

CVSS v3.1 Breakdown