Remcos
MITRE ATT&CK: S0332 View on attack.mitre.org
Aliases: RemcosRAT, Remvio, Socmer, Remcos, Rescoms
- First seen
- 2016-08-01 00:00:00
- Malware type
- rat, keylogger, spyware, screen-capture
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 16629 (12639 malicious)
- Last IoC activity
- 2026-09-02 04:25:04
- Profile updated
- 2026-07-07 15:46:51
Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications
Context
Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.
Recent IoC activity
12,700 malicious indicators in Maltiverse are attributed to Remcos (S0332). The 20 most recently updated:
Detection coverage
- 4 YARA rules
- 736 Sigma rules
Malware & tools used
- Internal Defacement (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- System Information Discovery (attack-pattern)
- Clipboard Data (attack-pattern)
- Process Injection (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Python (attack-pattern)
- Proxy (attack-pattern)
- Modify Registry (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Windows Service (attack-pattern)
- System Checks (attack-pattern)
- Windows Command Shell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Screen Capture (attack-pattern)
- Archive via Utility (attack-pattern)
- Indicator Removal (attack-pattern)
- Hidden Window (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Visual Basic (attack-pattern)
- Malicious File (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Keylogging (attack-pattern)
Used by threat actors
- Operation Spalax (campaign)
- TA2536 (threat-actor)
- Gamaredon Group (threat-actor)
- Gorgon Group (threat-actor)
- APT-C-36 (threat-actor)
- LazyScripter (threat-actor)
Detection rules
- EMBEERESEARCH_Win_Remcos_Rat_Unpacked (yara-rule)
- SEKOIA_Rat_Win_Remcos (yara-rule)
- SIGNATURE_BASE_MAL_Coralwave_Lenovospkvol_Remcosmicdrop (yara-rule)
- MALPEDIA_Win_Remcos_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- CERT-UA — 3931296 (report)
- socprime.com — Remcos Rat Detection Uac 0050 Hackers Launch Phishing Attacks Impersonating The Security Service Of Ukraine (report)
- socprime.com — New Phishing Attack Detection Attributed To The Uac 0050 And Uac 0096 Groups Spreading Remcos Spyware (report)
- CERT-UA — 3804703 (report)
- proofpoint.com — New Threat Actor Spoofs Philippine Government Covid 19 Health Data Widespread (report)
- Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
- Kaspersky — 117596 (report)
- researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
- research.checkpoint.com — Blind Eagle And Justice For All (report)
- Broadcom/Symantec — Elfin Apt33 Espionage (report)
- blog.morphisec.com — The Babadeda Crypter Targeting Crypto Nft Defi Communities (report)
- intel471.com — Privateloader Malware (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
- ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
- research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
- go.recordedfuture.com — Cta 2025 0130 (report)