home.social

#remcosrat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remcosrat, aggregated by home.social.

fetched live
  1. New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.

    Read: hackread.com/xworm-7-1-remcos-

    #CyberSecurity #Malware #XWorm #RemcosRAT

  2. 2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at malware-traffic-analysis.net/2

    I've also added three other blog entries from infections I generated in my lab on Tuesday, 2026-01-20. Those can be found at malware-traffic-analysis.net/2

    Those three other entries cover #LummaStealer, #VIPRecovery, and #Xworm. The VIP Recovery and Xworm infections followed the same chain of events, which includes #steganography through base64 text embedded in an image.

  3. Watch out as a new email attack uses fake employee reports to deliver Guloader and Remcos RAT malware, tricking users into running dangerous files disguised as performance reviews.

    Read: hackread.com/fake-employee-rep

    #Malware #Guloader #RemcosRAT #Phishing #CyberSecurity

  4. 2026-01-06 (Tuesday): #SmartApeSG CAPTCHA page uses #ClickFix technique to push #RemcosRAT.

    The #Remcos #RAT C2 server is at 192.144.56[.]80.

    A #pcap of the traffic, the Remcos RAT #malware, and a list of indicators are available at malware-traffic-analysis.net/2

  5. ⚠️ Watch out for ZIP and shortcut files on #Windows as attackers are using fake PDF icons to trick users into installing #Remcos trojan and take over computers.

    Read: hackread.com/fileless-remcos-r

    #CyberSecurity #Windows #Malware #RemcosRAT

  6. #MalspamMonday

    Malspam Monday is when I check the inboxes of my honey pot accounts for anything interesting distributed through email.

    Today, I found an example of #GuLoader for #Remcos #RAT

    Details at github.com/malware-traffic/ind

    #RemcosRAT #malspam

  7. Social media post I wrote about #RemcosRAT for my employer at linkedin.com/posts/unit42_remc and x.com/malware_traffic/status/1

    2025-03-10 (Monday): #Remcos #RAT activity. Email distribution used a zip archive attachment with a .7z file extension. During a test infection, we saw indicators of a #Keylogger and a Hacking tool to view browser passwords.

    More info at github.com/PaloAltoNetworks/Un

    A #pcap of the infection traffic and the associated #malware files are available at malware-traffic-analysis.net/2

  8. 🚩 Active #RemcosRAT campaign is distributed via GitHub through abuse of comments in legitimate repositories.

    Some malicious links:
    - https://github[.]com/ustaxes/UsTaxes/files/15421286/2022and2023TaxDocuments[.]zip
    - https://github[.]com/ustaxes/UsTaxes/files/15419438/2023TaxDocuments[.]zip
    - https://github[.]com/PolicyEngine/policyengine-us/files/15487603/2023.TAX.ORGANIZER.pdf[.]zip
    - https://github[.]com/hmrc/claim-tax-refund/files/15487332/TaxrefundlistPDF[.]zip

    They also got creative and registered the user "user-attachments" on GitHub 😄
    - https://github[.]com/user-attachments/files/15592343/Rachel.Completed.Organizer.Season.TAX.2023[.]zip

    Remcos C2 servers:
    - pattreon.duckdns[.]org:7035
    - deytrycooldown.duckdns[.]org:7070
    - newlink.duckdns[.]org:5111
    * Botnet: RemoteHost

    REF: bleepingcomputer.com/news/secu

  9. The Computer Emergency Response Team of Ukraine (CERT-UA) reports that the threat actor group UAC-0184 is increasingly using popular messengers and social engineering in 2024 to target the Ukrainian military, and steal documents/messenger data (e.g. Signal). Malware delivered include IDAT, RemcosRAT, VIOTTOKEYLOGGER, XWorm, SIGTOP and TUSC. A lot of IOC provided, and images depict infection chains or lure messages. 🔗 (Ukrainian language) cert.gov.ua/article/6278521

    #CERTUA #UAC0184 #Ukraine #cyberespionage #threatintel #IOC #RemcosRAT #IDAT #xworm

  10. Fortinet reports on a recent phishing campaign containing Scalable Vector Graphics (SVG) files. The malicious attachment downloads a ZIP file and begins the infection chain. ScrubCrypt, described as an "antivirus evasion tool", is used to load the final payload VenomRAT while maintaining a connection with the C2 server to install plugins like XWorm, NanoCore, RemcosRAT and a crypto wallet stealer. They provides detailed insights into how the threat actor distributes VenomRAT and other plugins. IOC listed. 🔗 fortinet.com/blog/threat-resea

    #ScrubCrypt #VenomRAT #RemcosRAT #XWorm #NanoCore #threatintel #IOC

  11. ESET Research reports that AceCryptor use surged in the second half of 2023. This included Remcos RAT campaigns for the first time, using compromised accounts for credibility in phishing emails. AceCryptor + Remcos campaigns targeted Poland, Bulgaria, Spain, and Serbia. Campaigns were described, MITRE ATT&CK TTPs and IOC provided. 🔗 welivesecurity.com/en/eset-res

    #AceCryptor #threatintel #IOC #Remcos #RemcosRAT #VidarStealer #Stopransomware #SmokeLoader

  12. The attackers’ goal was to covertly install Remcos RAT malware on organizations’ employees’ computers with the ability to further compromise and obtain valuable data.

    #Cybersecurity #RemcosRAT #Colombia #Cyberattacks

    cybersec84.wordpress.com/2023/

  13. To spread it, the attackers created malicious websites and specially crafted installers of various programs. Among them are tools for tuning processors, video cards and BIOSes, utilities for checking the status of computer hardware and many others

    #cybersecurity #hackers #malware #RemcosRAT #Windows #trojan

    cybersec84.wordpress.com/2023/