logo

Censys Threat Overview: Mapping Remcos C2 Activity at Internet Scale

ID: 6fed1cee-0e2b-57c5-b175-29971089d92c

STIX ID: report--6fed1cee-0e2b-57c5-b175-29971089d92c

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2025-11-14

Date Updated: 2026-04-27

Author: Andrew Northern; Principal Security Researcher

...
...

Remcos is a commercially distributed remote access tool (RAT) that enables remote command execution, file transfer, screen capture, keylogging, and credential theft over HTTP/HTTPS C2 channels; it is actively used in unauthorized access and data theft. The report describes common distribution methods (malspam, loaders), persistence mechanisms (Scheduled Tasks, Run keys), typical C2 ports and observable network artifacts, and Censys telemetry identifying over 150 active C2 servers and hosting trends across providers and countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.