Remcos RAT is a widely used Windows remote access Trojan that provides operators with full control over infected hosts.
Overview
Remcos RAT is a widely used Windows remote access Trojan that provides operators with full control over infected hosts. Its modular capabilities—remote command execution, keylogging, screen capture, credential harvesting, and file/clipboard management—make it a versatile tool for threat actors, and recent analyses map its C2 activity and the communication ports it uses to aid detection and attribution.
Related Threat Clusters
-
Multi-Stage Malware Campaign Utilizing Obfuscated VBS and PNG Loaders
A sophisticated multi-stage malware campaign has been identified, leveraging Unicode-obfuscated Visual Basic Script (VBS) loaders and PNG files to execute malicious payloads. The campaign employs a fileless PowerShell…
3 articles · Updated March 25, 2026 -
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
The SmartApeSG campaign employs a fake CAPTCHA page and ClickFix script to deliver various remote access trojans (RATs) including Remcos, NetSupport, StealC, and Sectop RAT. The attack begins with Remcos RAT, which…
2 articles · Updated June 18, 2026 -
SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of…
4 articles · Updated June 19, 2026 -
VHDX Files Exploited to Deploy Remcos RAT via Multi-Stage Attack
A recent cyber campaign utilizes a malicious ZIP archive containing a VHDX file to deliver the Remcos Remote Access Trojan (RAT). Upon mounting the VHDX, an obfuscated JavaScript file executes, triggering a series of…
2 articles · Updated June 18, 2026 -
New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing
A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…
2 articles · Updated May 29, 2026 -
SmartApeSG Campaign Distributes Multiple RATs via ClickFix Technique
The SmartApeSG campaign, also known as ZPHP and HANEYMANEY, has been observed delivering multiple remote access trojans (RATs) including Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2) through a social…
3 articles · Updated March 25, 2026 -
Microsoft Disrupts StegoAd Campaign with Malicious Edge Extensions
Microsoft has dismantled the StegoAd operation, removing 119 malicious Edge extensions that used steganography to hide malware within image and font files. The campaign, active since 2021, targeted over 2.6 million…
13 articles · Updated June 29, 2026 -
Phishing Campaign Uses GST Debit Note to Deploy Remcos RAT
A phishing campaign is targeting users in India with a malicious attachment named 'GST Debit Note Apr_26.com.' This attachment is a multi-stage steganographic loader that delivers the Remcos RAT, enabling attackers to…
2 articles · Updated June 22, 2026 -
Stealthy Remcos RAT Campaign Utilizes Obfuscated Scripts in Phishing Attack
A new Remcos RAT campaign has been identified, employing obfuscated scripts and trusted Windows binaries to execute a largely fileless infection chain. The attack initiates through a phishing email containing a ZIP…
2 articles · Updated April 2, 2026 -
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats
A China-linked hacking group, UNC6384, has exploited a Windows zero-day vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks, which occurred in…
18 articles · Updated November 3, 2025
Recent Intelligence Reports
- Microsoft Removes Over 100 StegoAd Edge Extensions Hiding Malware via Steganography — Technadu · June 29, 2026
- Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi — Cybersecuritynews · June 22, 2026
- 32826 — isc.sans.edu · June 18, 2026
- Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026
- Smartapesg Delivers Remcos — socprime.com · June 18, 2026
- SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz - Zscaler, Inc. — Zscaler · June 18, 2026
- VHDX Files Used to Deliver Remcos RAT — Socprime · June 18, 2026
- Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection — Feeds.Feedburner · May 29, 2026