logo

Deceptive Layoff-Themed HR Email Distributes Remcos RAT Malware

ID: 487e8163-d91c-50cd-8ecd-f348cd2084ab

STIX ID: report--487e8163-d91c-50cd-8ecd-f348cd2084ab

Feed Name: Seqrite Blog

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-30

Author: Prashil Moon

...
...

**Executive summary:** Seqrite Labs observed a spam campaign using layoff/HR-themed lures that delivered an NSIS-compiled Remcos RAT disguised inside a double-extension RAR (pdf.rar). The payload installs to c:\ProgramData\Remcos\remcos.exe, achieves persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, stores configuration under HKCU\Software\Rmc-<VictimID>, and provides remote access, keylogging, screenshots, and clipboard monitoring; the report includes MD5 hashes and a C2 IP for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.