Remy

Aliases: WINDSHIELD

First seen
2020-06-01 00:00:00
Malware type
trojan, rat
Family
Malware family
Profile updated
2026-07-07 12:50:39

Targeted industries: government-and-public-sector financial-services

Context

Remy, also known as WINDSHIELD, is a remote access trojan (RAT) that facilitates unauthorized access and control over affected systems. It primarily targets government and financial sectors, enabling attackers to exfiltrate data and engage in espionage activities.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Remy_Auto (yara-rule)

Reports & references

  • secureworks.com — Tin Woodlawn (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Remy (report)
  • threatvector.cylance.com — Report Oceanlotus Apt Group Leveraging Steganography (report)

External references