Remcos

Malware

⚠️ Overview

Remcos (Remote Control & Surveillance) is a commercial Remote Access Trojan (RAT) first detected in 2016 and marketed by the company Breaking Security as a legitimate remote administration tool, but it has been widely repurposed by cybercriminals for espionage, data theft, and botnet operations. According to Proofpoint and Cisco Talos reports, Remcos is often distributed via phishing emails with malicious Microsoft Office documents exploiting CVE-2017-11882 (Equation Editor vulnerability) or CVE-2018-0802, and its operator infrastructure is linked to the threat group TA569 (also tracked as “Squirrelwaffle”).

🔧 Technical Capabilities

Remcos provides full remote control over the infected host, including keylogging, screen and webcam capture, file exfiltration, password stealing (from browsers and FTP clients), and command execution. Propagation occurs through spear-phishing attachments, macro-laden documents, or exploit kits; the RAT uses a TCP-based command-and-control (C2) protocol over ports 80, 443, 2404, 3001, or 8080 with custom encryption (RC4 with a hardcoded key). Persistence is achieved via Windows registry Run keys, scheduled tasks, or service installation, while evasion techniques include process hollowing, API unhooking, and anti-debugging checks (e.g., IsDebuggerPresent, NtQueryInformationProcess). The C2 communication often mimics legitimate HTTP traffic, using User-Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36” to blend in.

📜 History & Notable Incidents

First publicly documented by Malwarebytes in 2016, Remcos became prominent in 2019 during a campaign targeting Latin American financial institutions and government entities, attributed to the TA569 group. In 2020, it was used in COVID-19-themed phishing lures against healthcare organizations globally, and in 2022, a variant called “Remcos RAT v4.9” incorporated a new injection technique bypassing Windows Defender. No CVEs are specific to Remcos itself, but it leverages the aforementioned Office memory-corruption exploits; no law enforcement actions against its developers have been reported as of 2025.

🔍 Detection Indicators

Known file hashes include MD5: 0x9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d (example) – real hashes vary per sample, but behavioral indicators include creation of the mutex “RemcosMutex” or “GlobalRemcosMutex”, registry keys under HKCUSoftwareRemcos, and network connections to IP addresses on port 2404 with RC4-encrypted payloads. The C2 domain often uses dynamic DNS providers like no-ip.com or duckdns.org with names containing “remcos”, “admin”, or “update”.

☠️ Risk & Impact

Remcos enables full system compromise, leading to credential theft, corporate espionage, and lateral movement within networks; it has been used to exfiltrate sensitive documents from government, defense, and financial sectors, causing operational disruption and potential regulatory fines. In 2021, a campaign against European energy companies resulted in the loss of intellectual property worth over $500,000 per incident, according to Group-IB threat intelligence.

🛡️ Mitigation

Mitigation includes blocking macro execution in Office documents via Group Policy, applying patches for CVE-2017-11882 and CVE-2018-0802, deploying endpoint detection rules (Sigma rule: win_malware_remcos.yml) that monitor for mutex “RemcosMutex” and anomalous outbound traffic on port 2404, and using network segmentation to limit lateral movement. Regular user awareness training against phishing with malicious attachments is also critical.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.