logo

Remcos RAT Being Distributed to Korean Users

ID: 84b0984d-cb65-5f8d-84f1-2e9743e4357b

STIX ID: report--84b0984d-cb65-5f8d-84f1-2e9743e4357b

Feed Name: ASEC

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-04-26

Author: ATCP

...
...

AhnLab ASEC reports an active Remcos RAT campaign targeting users in South Korea that impersonates gambling 'blocklist lookup' tools and VeraCrypt installers. The actors use multi-stage obfuscated VBS/PowerShell droppers, a .NET injector (which exfiltrates logs via Discord webhooks) and injects Remcos into legitimate processes; the report includes configuration examples, Korean-language artifacts, and IOCs (MD5s, URLs, IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.