logo

Remcos RAT Campaign Uses Trojanized VeraCrypt Installers to Steal Credentials

ID: bca35717-67d5-5721-ada8-482c6201063d

STIX ID: report--bca35717-67d5-5721-ada8-482c6201063d

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-19

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

AhnLab ASEC reports an active Remcos RAT campaign focused on South Korean users—particularly participants in illegal online gambling—using social‑engineered bait (fake “blocklist user” tools) and fraudulent VeraCrypt installers. The attack uses staged VBS and PowerShell downloaders, obfuscated payload placement (Base64 in JPG-like files), and a .NET injector that reports to Discord webhooks, decrypts and injects the Remcos payload into a legitimate process; Remcos provides credential theft, keylogging, screenshots, webcam/microphone surveillance, and remote control. Observed IOCs include distribution paths, randomized temp VBS files, and encrypted SETTINGS resources; recommended actions include isolating suspected systems, scanning and remediation, and credential resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.