RemCom
Aliases: RemoteCommandExecution
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-07-21 07:25:05
- Profile updated
- 2026-07-07 12:48:47
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
RemCom is a remote administration tool known for enabling attackers to execute commands on infected systems. It has been used in targeted attacks against government and technology sectors, often in operations requiring stealthy remote access capabilities.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Malware_Remcom_Strings (yara-rule)
- MALPEDIA_Win_Remcom_Auto (yara-rule)
Reports & references
- secureworks.com — Gold Franklin (report)
- Palo Alto Unit 42 — Stately Taurus Attacks Se Asian Government (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Remcom (report)
- doublepulsar.com — Second Zerologon Attacker Seen Exploiting Internet Honeypot C7Fb074451Ef (report)