Netskope Threat Labs

Remcos

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Remcos is a remote access trojan sold as a legitimate surveillance product that provides an extensive list of features to remotely control devices, and cyberattackers popularly abuse it in many campaigns. Its capabilities include remote desktop, keystroke logging, camera access, and file management, and its builder produces customized implants for each buyer. Distributed through phishing and loader chains, it remains one of the most commonly detected commercial RATs.

First seen
February 2022
Last seen
October 2026
RemcosRATRemcosrat

38 techniques across 10 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0007 Discovery

  • T1010Application Window Discovery
  • T1012Query Registry
  • T1033System Owner/User Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery
  • T1614System Location Discovery

TA0009 Collection

TA0011 Command and Control

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Binary.Trojan.Remcos
ByteCode-MSIL.Backdoor.Remcos
ByteCode-MSIL.Downloader.Remcos
ByteCode-MSIL.Spyware.Remcos
ByteCode-MSIL.Trojan.Remcos
ByteCode-MSIL.Trojan.RemcosRAT
DeepScan:Generic.Remcos.0AD18DBD
DeepScan:Generic.Remcos.0E4A57A9
DeepScan:Generic.Remcos.145BCFF3
DeepScan:Generic.Remcos.157C6A34