logo

Remcos RAT Distributed via Webhards

ID: d96a3f8a-6645-5ff1-93af-8105ea8a3703

STIX ID: report--d96a3f8a-6645-5ff1-93af-8105ea8a3703

Feed Name: ASEC

Threat Score
70/100

Date Published: 2024-01-14

Date Updated: 2026-04-26

Author: leeikgyu

...
...

AhnLab ASEC detected an active campaign distributing Remcos RAT in South Korea by disguising malware as game installers on webhards and torrents. The attackers include malicious VBS with a fake Game.exe that executes ffmpeg.exe, which splits a "sexyz" string to extract an encrypted binary and key from test.jpg, injects code into explorer.exe, then downloads Remcos from a C2 and injects it into ServiceModelReg.exe; the report provides file detections, MD5 hashes and URLs as IOCs and advises users to avoid running executables from file-sharing sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.