RemCom

Aliases: RemoteCommandExecution

Malware type
rat
Family
Malware family
Last IoC activity
2026-07-21 07:25:05
Profile updated
2026-07-07 12:48:47

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

RemCom is a remote administration tool known for enabling attackers to execute commands on infected systems. It has been used in targeted attacks against government and technology sectors, often in operations requiring stealthy remote access capabilities.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Malware_Remcom_Strings (yara-rule)
  • MALPEDIA_Win_Remcom_Auto (yara-rule)

Reports & references

  • secureworks.com — Gold Franklin (report)
  • Palo Alto Unit 42 — Stately Taurus Attacks Se Asian Government (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Remcom (report)
  • doublepulsar.com — Second Zerologon Attacker Seen Exploiting Internet Honeypot C7Fb074451Ef (report)

External references