logo

Cisco Links Remote Access Tool Remcos to Cybercriminal Underground

ID: 1de7f3ac-0afd-52d3-8cf8-edd2898c5caa

STIX ID: report--1de7f3ac-0afd-52d3-8cf8-edd2898c5caa

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2018-08-23

Date Updated: 2026-04-26

Author: Elizabeth Montalbano

...
...

Cisco Talos reports that Remcos, a commercially sold remote access tool from Breaking Security, is widely abused by multiple actors in spear-phishing campaigns that use malicious Office macros to drop a downloader and retrieve the RAT, enabling botnet creation and full Windows system control; related products (keylogger, mass mailer, DynDNS) further facilitate botnet operations, and Talos publishes a decoder to extract C2 information and recommends mitigation with security controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.