logo

Beware the ClickFix Trap: REMCOS RAT Hiding in “Helpful” PUAs

ID: 1cd0d38e-619c-5b0c-9825-1284145262f4

STIX ID: report--1cd0d38e-619c-5b0c-9825-1284145262f4

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-28

Author: Hema Loganathan

...
...

Cybereason GSOC observed a rise in REMCOS RAT infections delivered via trojanized Shotcut portable ZIPs that replace legitimate DLLs to load multi-stage loaders; attackers use MSHTA/PowerShell staging, DLL sideloading, callback-style shellcode injection, and in-memory loading to deploy a full-featured RAT capable of keylogging, credential theft, surveillance, privilege escalation, and persistent C2 communications, with identified IOCs and containment recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.