#remcos — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #remcos, aggregated by home.social.
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
Still Circling: Inside the Operator Behind the GitHub Loader
An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.
Pulse ID: 6a9226b8695b02a09a6160ef
Pulse Link: https://otx.alienvault.com/pulse/6a9226b8695b02a09a6160ef
Pulse Author: AlienVault
Created: 2026-08-29 00:24:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #AsyncRAT #CyberSecurity #DCRat #DNS #Email #GitHub #Government #InfoSec #Mac #Malware #OTX #OpenThreatExchange #Password #Phishing #RAT #Remcos #Word #Worm #XWorm #bot #AlienVault
-
ISC Diary: #SmartApeSG campaign pushes #Remcos #RAT, #NetSupportRAT, #StealC and #SectopRAT (#ArechC https://isc.sans.edu/diary/32826