Remcos

MITRE ATT&CK: S0332 View on attack.mitre.org

Aliases: RemcosRAT, Remvio, Socmer, Remcos, Rescoms

First seen
2016-08-01 00:00:00
Malware type
rat, keylogger, spyware, screen-capture
Family
Malware family
Operating systems
windows
Related IoCs
16629 (12639 malicious)
Last IoC activity
2026-09-02 04:25:04
Profile updated
2026-07-07 15:46:51

Targeted industries: financial-services government-and-public-sector healthcare-and-pharmaceutical technology-and-telecommunications

Context

Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.

Recent IoC activity

12,700 malicious indicators in Maltiverse are attributed to Remcos (S0332). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 217.60.195.33 2026-09-03 1
IP address 217.60.195.210 2026-09-03 1
IP address 91.92.242.91 2026-09-03 7
IP address 46.246.84.10 2026-09-03 6
file sample 59ee3524c509498a52eed846307bb58cc9a614568041076de278c9e79ce89c40 2026-09-03 1
IP address 213.152.187.200 2026-09-03 8
IP address 213.152.187.220 2026-09-03 8
hostname oficialrem.duckdns.org 2026-09-03 1
file sample 86b19710e100964d95cfa01201152d4e73f1297f7286207feeb01cdb7e55efc8 2026-09-03 2
file sample 86a38c7be7f024035b513355c83265e1e210a2c82329839538a734ad75275d7b 2026-09-03 4
file sample 86b4d9c62ca9eccd9341136d5d4831548ccb79ed000f29e8a8cc0afcbe639c90 2026-09-03 3
hostname capriteam.ddns.net 2026-09-03 1
hostname 8kbet5.com 2026-09-03 1
hostname backup419.duckdns.org 2026-09-03 1
hostname codecubicle.co.in 2026-09-03 1
hostname nakamura.hopto.org 2026-09-03 1
hostname sofie12.duckdns.org 2026-09-03 1
hostname pdhasync.duckdns.org 2026-09-03 2
hostname services11.accesscam.org 2026-09-03 1
hostname ytuna7307.duckdns.org 2026-09-03 1

Detection coverage

  • 4 YARA rules
  • 736 Sigma rules

Malware & tools used

  • Internal Defacement (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Process Injection (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Python (attack-pattern)
  • Proxy (attack-pattern)
  • Modify Registry (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Windows Service (attack-pattern)
  • System Checks (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Screen Capture (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Hidden Window (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Visual Basic (attack-pattern)
  • Malicious File (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Keylogging (attack-pattern)

Used by threat actors

Detection rules

  • EMBEERESEARCH_Win_Remcos_Rat_Unpacked (yara-rule)
  • SEKOIA_Rat_Win_Remcos (yara-rule)
  • SIGNATURE_BASE_MAL_Coralwave_Lenovospkvol_Remcosmicdrop (yara-rule)
  • MALPEDIA_Win_Remcos_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • CERT-UA — 3931296 (report)
  • socprime.com — Remcos Rat Detection Uac 0050 Hackers Launch Phishing Attacks Impersonating The Security Service Of Ukraine (report)
  • socprime.com — New Phishing Attack Detection Attributed To The Uac 0050 And Uac 0096 Groups Spreading Remcos Spyware (report)
  • CERT-UA — 3804703 (report)
  • proofpoint.com — New Threat Actor Spoofs Philippine Government Covid 19 Health Data Widespread (report)
  • Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
  • Kaspersky — 117596 (report)
  • researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
  • research.checkpoint.com — Blind Eagle And Justice For All (report)
  • Broadcom/Symantec — Elfin Apt33 Espionage (report)
  • blog.morphisec.com — The Babadeda Crypter Targeting Crypto Nft Defi Communities (report)
  • intel471.com — Privateloader Malware (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2022%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q3%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q1%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — 2023%20Q2%20Botnet%20Threat%20Update (report)
  • ptsecurity.com — Steganoamor Campaign Ta558 Mass Attacking Companies And Public Institutions All Around The World (report)
  • research.checkpoint.com — Foxit Pdf Flawed Design Exploitation (report)
  • go.recordedfuture.com — Cta 2025 0130 (report)

External references