logo

Intelligence Insights: January 2026

ID: 886d63f2-9498-50af-878c-36fd35fa0007

STIX ID: report--886d63f2-9498-50af-878c-36fd35fa0007

Feed Name: Red Canary

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-29

Author: The Red Canary Team

...
...

Remcos, a commercially available remote access tool frequently abused by adversaries, has been observed rising in use as a payload in campaigns (notably by Scarlet Goldfinch). The report documents delivery via paste-and-run lures, use of LOLBins such as the TCP/IP finger command and forfiles, curl/tar download-and-extract chains, and DLL sideloading into legitimate binaries; it includes example commands and IPs and notes synchronous reporting by multiple researchers that indicate increasing popularity and active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.