logo

Tracing Remcos RAT

ID: ec841221-71e3-52b5-9b0d-02bcd1817d9d

STIX ID: report--ec841221-71e3-52b5-9b0d-02bcd1817d9d

Feed Name: IntelInsights (Substack)

Threat Score
58/100

Date Published: 2024-12-05

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report investigates a suspected Remcos RAT infection delivered via phishing (filetransfer.io), analyzes the sample’s communications (e.g., 185.29.10.213:63650), and pivots across ASN 60567 and SSH fingerprint/port combinations to identify related infrastructure. It presents IP IOCs with mixed confidence—moderate for broader infrastructure leads and high for a small set of malware-communicating IPs—while cautioning that attribution to Remcos is not definitive due to overlapping use by varied threat activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.