Censys Threat Overview: Mapping Remcos C2 Activity at Internet Scale
ID: 6fed1cee-0e2b-57c5-b175-29971089d92c
STIX ID: report--6fed1cee-0e2b-57c5-b175-29971089d92c
Feed Name: Censys Blog
Date Published: 2025-11-14
Date Updated: 2026-04-27
Author: Andrew Northern; Principal Security Researcher
Remcos is a commercially distributed remote access tool (RAT) that enables remote command execution, file transfer, screen capture, keylogging, and credential theft over HTTP/HTTPS C2 channels; it is actively used in unauthorized access and data theft. The report describes common distribution methods (malspam, loaders), persistence mechanisms (Scheduled Tasks, Run keys), typical C2 ports and observable network artifacts, and Censys telemetry identifying over 150 active C2 servers and hosting trends across providers and countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
