Intelligence Insights: January 2026
ID: 886d63f2-9498-50af-878c-36fd35fa0007
STIX ID: report--886d63f2-9498-50af-878c-36fd35fa0007
Feed Name: Red Canary
Remcos, a commercially available remote access tool frequently abused by adversaries, has been observed rising in use as a payload in campaigns (notably by Scarlet Goldfinch). The report documents delivery via paste-and-run lures, use of LOLBins such as the TCP/IP finger command and forfiles, curl/tar download-and-extract chains, and DLL sideloading into legitimate binaries; it includes example commands and IPs and notes synchronous reporting by multiple researchers that indicate increasing popularity and active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
