home.social

#remcosrat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #remcosrat, aggregated by home.social.

fetched live
  1. ClickFix-Themed Campaign Deploys Starland RAT and WLDR Framework

    A Russian-speaking, financially motivated threat actor designated UAT-11795 has been conducting a sophisticated malware campaign since June 2025, primarily targeting users in the United States. The operation utilizes ClickFix-style social engineering techniques with trojanized software installers for applications like MobaXterm, Cisco WebEx, Zoom, DBeaver, and FACEIT. The campaign deploys Starland RAT, a custom Python-based remote access tool that establishes persistence, performs reconnaissance, and collects cryptocurrency wallet information. The malware employs blockchain-based fallback C2 mechanisms via Polygon smart contracts. Additionally, the operation deploys the previously undocumented WLDR PowerShell framework, CastleStealer, and Remcos RAT, demonstrating a modular architecture focused on credential theft, cryptocurrency harvesting, and long-term post-compromise access.

    Pulse ID: 6a71a6ac7bd8297ea6d2093f
    Pulse Link: otx.alienvault.com/pulse/6a71a
    Pulse Author: AlienVault
    Created: 2026-08-04 08:45:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Cisco #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #PowerShell #Python #RAT #Remcos #RemcosRAT #Russia #SMS #SocialEngineering #Trojan #UnitedStates #Zoom #bot #cryptocurrency #AlienVault

  2. New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.

    Read: hackread.com/xworm-7-1-remcos-

    #CyberSecurity #Malware #XWorm #RemcosRAT

  3. 2026-01-22 (Thursday): #RemcosRAT infection persistent on an infected Windows host. This was caused by #ClickFix instructions from #SmartApeSG through a fake CAPTCHA page. Details of this #Remcos #RAT infection are available at malware-traffic-analysis.net/2

    I've also added three other blog entries from infections I generated in my lab on Tuesday, 2026-01-20. Those can be found at malware-traffic-analysis.net/2

    Those three other entries cover #LummaStealer, #VIPRecovery, and #Xworm. The VIP Recovery and Xworm infections followed the same chain of events, which includes #steganography through base64 text embedded in an image.

  4. Watch out as a new email attack uses fake employee reports to deliver Guloader and Remcos RAT malware, tricking users into running dangerous files disguised as performance reviews.

    Read: hackread.com/fake-employee-rep

    #Malware #Guloader #RemcosRAT #Phishing #CyberSecurity

  5. 2026-01-06 (Tuesday): #SmartApeSG CAPTCHA page uses #ClickFix technique to push #RemcosRAT.

    The #Remcos #RAT C2 server is at 192.144.56[.]80.

    A #pcap of the traffic, the Remcos RAT #malware, and a list of indicators are available at malware-traffic-analysis.net/2

  6. ⚠️ Watch out for ZIP and shortcut files on #Windows as attackers are using fake PDF icons to trick users into installing #Remcos trojan and take over computers.

    Read: hackread.com/fileless-remcos-r

    #CyberSecurity #Windows #Malware #RemcosRAT

  7. #MalspamMonday

    Malspam Monday is when I check the inboxes of my honey pot accounts for anything interesting distributed through email.

    Today, I found an example of #GuLoader for #Remcos #RAT

    Details at github.com/malware-traffic/ind

    #RemcosRAT #malspam

  8. Social media post I wrote about #RemcosRAT for my employer at linkedin.com/posts/unit42_remc and x.com/malware_traffic/status/1

    2025-03-10 (Monday): #Remcos #RAT activity. Email distribution used a zip archive attachment with a .7z file extension. During a test infection, we saw indicators of a #Keylogger and a Hacking tool to view browser passwords.

    More info at github.com/PaloAltoNetworks/Un

    A #pcap of the infection traffic and the associated #malware files are available at malware-traffic-analysis.net/2

  9. 🚩 Active #RemcosRAT campaign is distributed via GitHub through abuse of comments in legitimate repositories.

    Some malicious links:
    - https://github[.]com/ustaxes/UsTaxes/files/15421286/2022and2023TaxDocuments[.]zip
    - https://github[.]com/ustaxes/UsTaxes/files/15419438/2023TaxDocuments[.]zip
    - https://github[.]com/PolicyEngine/policyengine-us/files/15487603/2023.TAX.ORGANIZER.pdf[.]zip
    - https://github[.]com/hmrc/claim-tax-refund/files/15487332/TaxrefundlistPDF[.]zip

    They also got creative and registered the user "user-attachments" on GitHub 😄
    - https://github[.]com/user-attachments/files/15592343/Rachel.Completed.Organizer.Season.TAX.2023[.]zip

    Remcos C2 servers:
    - pattreon.duckdns[.]org:7035
    - deytrycooldown.duckdns[.]org:7070
    - newlink.duckdns[.]org:5111
    * Botnet: RemoteHost

    REF: bleepingcomputer.com/news/secu

  10. The Computer Emergency Response Team of Ukraine (CERT-UA) reports that the threat actor group UAC-0184 is increasingly using popular messengers and social engineering in 2024 to target the Ukrainian military, and steal documents/messenger data (e.g. Signal). Malware delivered include IDAT, RemcosRAT, VIOTTOKEYLOGGER, XWorm, SIGTOP and TUSC. A lot of IOC provided, and images depict infection chains or lure messages. 🔗 (Ukrainian language) cert.gov.ua/article/6278521

    #CERTUA #UAC0184 #Ukraine #cyberespionage #threatintel #IOC #RemcosRAT #IDAT #xworm

  11. Fortinet reports on a recent phishing campaign containing Scalable Vector Graphics (SVG) files. The malicious attachment downloads a ZIP file and begins the infection chain. ScrubCrypt, described as an "antivirus evasion tool", is used to load the final payload VenomRAT while maintaining a connection with the C2 server to install plugins like XWorm, NanoCore, RemcosRAT and a crypto wallet stealer. They provides detailed insights into how the threat actor distributes VenomRAT and other plugins. IOC listed. 🔗 fortinet.com/blog/threat-resea

    #ScrubCrypt #VenomRAT #RemcosRAT #XWorm #NanoCore #threatintel #IOC

  12. ESET Research reports that AceCryptor use surged in the second half of 2023. This included Remcos RAT campaigns for the first time, using compromised accounts for credibility in phishing emails. AceCryptor + Remcos campaigns targeted Poland, Bulgaria, Spain, and Serbia. Campaigns were described, MITRE ATT&CK TTPs and IOC provided. 🔗 welivesecurity.com/en/eset-res

    #AceCryptor #threatintel #IOC #Remcos #RemcosRAT #VidarStealer #Stopransomware #SmokeLoader

  13. The attackers’ goal was to covertly install Remcos RAT malware on organizations’ employees’ computers with the ability to further compromise and obtain valuable data.

    #Cybersecurity #RemcosRAT #Colombia #Cyberattacks

    cybersec84.wordpress.com/2023/

  14. To spread it, the attackers created malicious websites and specially crafted installers of various programs. Among them are tools for tuning processors, video cards and BIOSes, utilities for checking the status of computer hardware and many others

    #cybersecurity #hackers #malware #RemcosRAT #Windows #trojan

    cybersec84.wordpress.com/2023/