logo

The Stealthy Stalker: Remcos RAT

ID: de7d46a6-5cce-5b2f-b09b-747caa11e9c6

STIX ID: report--de7d46a6-5cce-5b2f-b09b-747caa11e9c6

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2024-12-11

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs technical analysis describes a rise in Remcos RAT activity and examines two variants: one delivered via an obfuscated VBS/PowerShell loader that fetches DLLs from FTP/PasteCode and injects a Remcos payload into RegAsm.exe, and another delivered through a malicious DOCX that leverages CVE-2017-11882 to drop an RTF which ultimately loads Remcos in memory via a dnlib assembly; the report includes detailed infection chains, persistence and injection techniques, memory artifacts, mutexes, numerous IOCs (hashes and URLs), and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.