Remcos RAT Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
23
occurrences
First Seen
October 31, 2025
Last Seen
June 29, 2026

Remcos RAT is a widely used Windows remote access Trojan that provides operators with full control over infected hosts.

Overview

Remcos RAT is a widely used Windows remote access Trojan that provides operators with full control over infected hosts. Its modular capabilities—remote command execution, keylogging, screen capture, credential harvesting, and file/clipboard management—make it a versatile tool for threat actors, and recent analyses map its C2 activity and the communication ports it uses to aid detection and attribution.

Related Threat Clusters

Recent Intelligence Reports

  • Microsoft Removes Over 100 StegoAd Edge Extensions Hiding Malware via Steganography — Technadu · June 29, 2026
  • Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi — Cybersecuritynews · June 22, 2026
  • 32826 — isc.sans.edu · June 18, 2026
  • Smartapesg Returns With Unique Obfuscation Techniques — www.blumira.com · June 18, 2026
  • Smartapesg Delivers Remcos — socprime.com · June 18, 2026
  • SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz - Zscaler, Inc. — Zscaler · June 18, 2026
  • VHDX Files Used to Deliver Remcos RAT — Socprime · June 18, 2026
  • Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection — Feeds.Feedburner · May 29, 2026

CVSS v3.1 Breakdown