logo

Remcos RAT Masquerade as VeraCrypt Installers Steals Users Login Credentials

ID: 8696c5d3-1d1c-5b10-8747-441fe61419fe

STIX ID: report--8696c5d3-1d1c-5b10-8747-441fe61419fe

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A multi-stage campaign is distributing the Remcos RAT to South Korean users by masquerading malicious installers as VeraCrypt and fake database lookup tools (often targeting illegal gambling users). The attack chain uses obfuscated VBS and PowerShell downloaders, Base64-embedded payloads, and a .NET injector that contacts attackers via Discord webhooks before injecting Remcos into AddInProcess32.exe; the RAT provides full remote control and data-theft features (keylogging, screenshots, webcam/microphone access, and credential extraction).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.