Skip to main content

Threats Tagged 'remcos'

View all threats tagged with 'remcos'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: remcos

Threats Tagged 'remcos'

Click on any threat for detailed analysis and mitigation recommendations

Brazilian banking malware operation REF9334 has been deploying KREMLIN toolkit since May 2025, targeting Brazilian financial institutions through malicious browser extensions. The operation uses multi-stage JavaScript loaders, custom C++ installers, and exploits Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs. Infrastructure leverages Ethereum smart contracts as dead-drop resolvers for dynamic C2 configuration. Seven distinct campaigns over 15 months show evolution from PULSAR RAT to REMCOS RAT delivery. Attackers impersonate twelve Brazilian banks through Portuguese-language lures, with transaction patterns clustering during São Paulo working hours. The malicious extensions intercept credentials, session tokens, and sensitive banking data through keylogging and request interception capabilities. Over 1,500 infections have been temporarily disrupted through network canary registration, with 98.75% of victims located in Brazil.

Join the discussion

An investigation into malware delivery infrastructure reveals an operator using GitHub repositories to stage malicious loaders and RAT payloads. Starting from commit metadata, researchers traced an email address to a compromised machine via stealer log databases. The infected workstation exposed a complete operational pipeline including multiple RAT families (AsyncRAT, DcRat, Remcos, XWorm), phishing templates impersonating Colombian government institutions, bulk email software, and commercial crypter services. The operator maintains delivery infrastructure across GitHub, Bitbucket, AWS S3, and DuckDNS for command-and-control. Phishing campaigns target Colombian organizations using judicial notification and traffic violation lures with password-protected archives. The investigation demonstrates how infrastructure analysis and operational security failures can expose entire malware production workflows beyond individual samples.

Join the discussion

Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

Join the discussion

Cruciferra is a sophisticated crypter service utilized by multiple unrelated cybercriminal threat clusters to deliver remote access trojans and infostealers. Written in Mono, it employs extensive defense-evasion capabilities including indirect system calls, API unhooking, BYOVD-based EDR tampering, privilege escalation, and customized Process Ghosting for payload execution. The service features over 90 variations of cryptographic functions to obfuscate data and payloads, complicating static analysis and signature-based detection. Cruciferra was first advertised in fall 2025 with pricing tiers ranging from $450 to $2000 monthly. It has been observed in campaigns delivering various malware families including zgRAT, AgentTesla, AsyncRAT, XLoader, XWorm, Phantom Stealer, Formbook, and Remcos, primarily targeting financial services, healthcare, and government entities through opportunistic email-based attacks.

Join the discussion

Since late March 2026, a large-scale phishing campaign has been deploying malware including Agent Tesla, Remcos, XWorm, and Best Private LOGGER through fileless techniques and low-detection Lua-based loaders. Attackers impersonate well-known companies using business cooperation lures to distribute malicious archives containing obfuscated JavaScript files. These scripts deploy either AutoIt or LuaJIT interpreters alongside disguised scripts masquerading as TrueType Font (.ttf) files. The Lua loaders employ sophisticated anti-analysis techniques including custom ROT ciphers, decoy memory allocation, and Donut shellcode generation for reflective in-memory payload execution. The campaign evolved from simpler implementations in October 2025 to highly complex versions by June 2026, incorporating API unhooking and advanced debugging countermeasures. Victims are ultimately infected with Remote Access Trojans and infostealers that enable full system control and extensive data exfiltration.

Join the discussion

Between February 2024 and April 2026, multiple cyberespionage actors, suspected to be China-nexus and India-nexus threat groups, conducted sustained intrusions into Pakistani law enforcement organizations, particularly Balochistan Police. The compromised infrastructure included network appliances and servers hosting web applications managing criminal records, biometric data, hotel registrations, and citizen complaints. A suspected China-nexus actor weaponized the Complaint Management System web application by deploying custom implants disguised as portal updates, targeting both police personnel and citizens. China's likely motivation stems from concerns over the safety of Chinese nationals in Pakistan, particularly regarding attacks by separatist groups. India's suspected interest relates to its adversarial relationship with Pakistan, with Balochistan Police offering intelligence on security operations in a strategically sensitive province. The attackers deployed PlugX, ShadowPad, Cobalt Strike, Remcos, an...

Join the discussion

A malicious Go module posing as a DNS/subdomain scanner exposed a sophisticated Windows malware staging operation utilizing commit-farming workflows, public dead drops, and protected archives to deploy RAT and infostealer malware. The operation, tracked as 'Muck and Load', leverages a GitHub-based infrastructure comprising 222 confirmed repositories across 190 accounts designed to appear active and legitimate through automated GitHub Actions workflows. The attack chain begins with a deceptive Go module that downloads encoded PowerShell content, which then queries multiple public platforms including Pastebin, Telegram, YouTube, and Instagram as dead drops for encrypted payload locations. The loader retrieves password-protected archives containing AsyncRAT, Quasar, Remcos, and Vidar infostealer payloads, executing them from masqueraded Microsoft-themed directories. At least 14 malware files were confirmed across the repository network.

Join the discussion

A widespread phishing campaign distributing AsyncRAT and Remcos RATs has been observed targeting organizations across manufacturing, media, professional services, agriculture, and chemical industries globally. The attack leverages malicious Excel spreadsheets sent via emails impersonating business communications like purchase orders and payment advice. When macros are enabled, VBA code retrieves HTA payloads through URL shorteners and Cloudflare Workers infrastructure. The multi-stage infection chain employs heavy obfuscation including Base64 encoding, steganography in PNG files, and character substitution. The campaign intensified during June 2026, affecting organizations across Europe, Asia-Pacific, and the Americas. Infrastructure includes distinctive HTA naming conventions using concatenated positive English words. The operation likely uses automation for payload generation and may leverage LLMs for development efficiency.

Join the discussion

A global phishing campaign targets business functions with emails carrying malicious Excel attachments that initiate a multi-stage infection chain when macros are enabled. The attack uses layered obfuscation, including HTA scripts, PowerShell, encoded payloads, and steganography in PNG files, to deliver and execute Remote Access Trojans such as Remcos and AsyncRAT in a largely fileless manner. It achieves scale and persistence through high variability, automation, disposable infrastructure, and consistent patterns that help evade detection despite relatively simple techniques.

Join the discussion
0

On May 14, 2026, a supply chain attack was discovered targeting the Okendo Reviews widget, a customer review platform used by over 18,000 brands. The threat actor injected malicious JavaScript code into the legitimate widget, which is deployed on high-traffic e-commerce pages including storefronts and product pages. The compromised JavaScript acted as a staged loader, using obfuscation, localStorage tracking, User-Agent filtering, and XOR-based decoding to conceal next-stage infrastructure. The attack employed ClickFix-style social engineering to deceive users into executing malicious commands, ultimately delivering remote access trojans like NetSupport and Remcos, or information stealers such as StealC. Affected websites received hundreds of thousands to millions of monthly visitors, with nearly 15,000 blocks recorded in a single day.

Join the discussion

Showing 1 to 10 of 21 results

Filters:Tag: remcos
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses