LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0332: Remcos

Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.[1][2]

EnterpriseS0332ToolObject v1.4Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Remcos matters because it is a Windows remote control and surveillance tool that ATT&CK records as having been used in malware campaigns. For leaders, the risk is not the brand name alone; it is the combination of remote access, discovery, credential collection through keylogging, screen capture, file transfer, registry activity, command execution, proxying, and evidence removal behaviors associated with the tool in ATT&CK relationships.

Executive priority

Treat Remcos coverage as a practical test of Windows endpoint visibility and incident response readiness. Security leaders should ask whether the organization can identify unauthorized remote-control tooling, reconstruct command execution and registry changes, detect collection activity such as keylogging or screen capture, and preserve enough endpoint and network evidence when file deletion or obfuscation is present. The object is also relevant for threat intelligence prioritization because ATT&CK links it to multiple groups and a campaign, including Operation Spalax, Gamaredon Group, Gorgon Group, and LazyScripter, but local exposure should be determined from internal telemetry rather than assumed.

Technical view

ATT&CK does not provide a dedicated detection section for Remcos, so SOC and detection teams should validate coverage through the related behaviors: Windows command shell, Visual Basic, Python, and JavaScript execution; process injection; registry query and modification; user, process, window, system, file, and directory discovery; keylogging; screen capture; ingress tool transfer; proxy use; obfuscation or encoded files; file deletion; and other indicator removal. Because the tool is described as closed-source remote control and surveillance software, detection should focus on unauthorized behavior chains on Windows rather than a single static indicator.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Script execution telemetry for Windows command shell, Visual Basic, Python, and JavaScript/JScript where available
  • Registry query and modification events
  • Endpoint alerts or behavioral events for process injection
  • File creation, modification, transfer, and deletion events

Detection direction

  • Prioritize behavior-chain detection: execution plus discovery plus registry change plus network connection is more decision-useful than a standalone tool name match.
  • Tune detections for legitimate administrative and remote support tools to reduce false positives while preserving alerts for unauthorized surveillance behaviors such as keylogging and screen capture.
  • Validate that file deletion and obfuscation do not erase the only evidence needed for triage; ensure endpoint and centralized logs retain process, file, registry, and network context.
  • Use the ATT&CK relationships to test analytics mapped to T1010, T1012, T1027, T1027.013, T1033, T1055, T1056.001, T1057, T1059.003, T1059.005, T1059.006, T1059.007, T1070, T1070.004, T1082, T1083, T1090, T1105, T1112, and T1113.
  • Review threat intelligence matches cautiously: the supplied ATT&CK data supports historical association with several groups and one campaign, but does not by itself prove current targeting or attribution in a local incident.

Mitigation priorities

  • Establish and enforce policy for approved remote administration and surveillance-capable software on Windows systems.
  • Harden Windows endpoints against unauthorized script execution, command shell abuse, registry modification, and process injection where business operations allow.
  • Ensure endpoint protection, EDR, and logging controls cover discovery, credential collection, screen capture, file transfer, and cleanup behaviors.
  • Limit user privileges and administrative access so registry modification, persistence-related changes, and surveillance functions require stronger authorization.
  • Prepare IR playbooks for suspected remote access tool activity, including host isolation criteria, credential review, log preservation, and threat intelligence validation.
Additional notes and limits

The most useful defensive takeaway is that Remcos should be assessed as a remote access and surveillance behavior cluster on Windows. ATT&CK links the tool to malware campaigns and to multiple actors/campaigns, but the supplied object has no aliases, labels, or official detection guidance. Detection engineering should therefore be mapped from the related techniques rather than from a single Remcos signature.

This take uses only the supplied ATT&CK object fields, external references, and relationships. The object lists Windows as the platform and does not specify tactics directly. Some related techniques have broader platform metadata, but that should not be interpreted as Remcos platform support beyond the supplied Windows platform. No claim is made about active exploitation, current targeting, customer exposure, or guaranteed detection.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Remcos

Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

38 rows
DomainIDNameRelationship / procedure
EnterpriseT1491.001Internal DefacementSub-technique

Remcos has the ability to modify the desktop wallpaper.[3]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.[4]

EnterpriseT1082System Information Discovery

Remcos can collect the OS version and process architecture of compromised hosts.[3]

EnterpriseT1115Clipboard Data

Remcos steals and modifies data from the clipboard.[1][3]

EnterpriseT1055Process Injection

Remcos has a command to hide itself by injecting into another process.[4]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Remcos has been spread through emails containing malicious documents.[3]

EnterpriseT1059.006PythonSub-technique

Remcos uses Python scripts.[1]

EnterpriseT1090Proxy

Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.[1][3]

EnterpriseT1112Modify Registry

Remcos has full control of the Registry, including the ability to modify it.[1][3]

EnterpriseT1573.002Asymmetric CryptographySub-technique

Remcos can use TLS to encrypt C2 communication.[3]

EnterpriseT1027Obfuscated Files or Information

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths.[2] Remcos can also employ control flow flattening to hinder analysis.[6]

EnterpriseT1543.003Windows ServiceSub-technique

Remcos can terminate, suspend, and resume a process by PID.[3]

EnterpriseT1497.001System ChecksSub-technique

Remcos searches for Sandboxie and VMware on the system.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Remcos can launch a remote command line to execute commands on the victim’s machine.[4][3]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Remcos can use string encryption to hinder analysis.[3]

EnterpriseT1548.002Bypass User Account ControlSub-technique

Remcos has a command for UAC bypassing.[4]

EnterpriseT1113Screen Capture

Remcos takes automated screenshots of the infected machine.[1][3]

EnterpriseT1560.001Archive via UtilitySub-technique

Remcos can zip files and folders for upload.[3]

EnterpriseT1070Indicator Removal

Remcos can clean saved cookies and logins from the web browser.[3]

EnterpriseT1564.003Hidden WindowSub-technique

Remcos can set `ProcessWindowStyle.Hidden` to hide windows.[6]

EnterpriseT1105Ingress Tool Transfer

Remcos can upload and download files to and from the victim’s machine.[1][3]

EnterpriseT1059.005Visual BasicSub-technique

Remcos can execute VBS remotely.[3]

EnterpriseT1204.002Malicious FileSub-technique

Remcos has been executed by luring victims into opening malicious email attachments including Excel files.[3]

EnterpriseT1568Dynamic Resolution

Remcos has used dynamic DNS domains in C2 communications.[6]

EnterpriseT1056.001KeyloggingSub-technique

Remcos has a command for keylogging.[4][2]

EnterpriseT1125Video Capture

Remcos can access a system’s webcam and take pictures.[4]

EnterpriseT1012Query Registry

Remcos can obtain Registry data from targeted systems.[3]

EnterpriseT1564Hide Artifacts

Remcos can modify file attributes to hide the file.[3]

EnterpriseT1083File and Directory Discovery

Remcos can search for files on the infected machine.[1][3]

EnterpriseT1123Audio Capture

Remcos can capture data from the system’s microphone.[4][3]

EnterpriseT1070.004File DeletionSub-technique

Remcos can delete files and folders from victim machines.[3]

EnterpriseT1057Process Discovery

Remcos can discover running processes on compromised machines.[3]

EnterpriseT1614System Location Discovery

Remcos can identify the location of targeted devices.[3]

EnterpriseT1010Application Window Discovery

Remcos can list all windows on victim systems.[3]

EnterpriseT1529System Shutdown/Reboot

Remcos can shutdown and restart remote devices.[3]

EnterpriseT1033System Owner/User Discovery

Remcos can enumerate the username on targeted hosts.[3]

EnterpriseT1059.007JavaScriptSub-technique

Remcos has the ability to execute JavaScript remotely.[3]

EnterpriseT1132.001Standard EncodingSub-technique

Remcos can serialize collected data with Protobuf.[6]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0047: Gamaredon Group

Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name Gamaredon Group derives from a misspelling of the word "Armageddon," found in early campaigns.[1][2][3][4][5]

In November 2021, the Ukrainian government publicly attributed Gamaredon Group to Russia’s Federal Security Service (FSB) Center 18, an assessment later supported by multiple independent cybersecurity researchers. [6][5]

GroupEnterprise

G0099: APT-C-36

APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities in the financial, energy, and professional manufacturing sectors across Colombia and other Latin American countries.[1][2][3][4]

GroupEnterprise

G0078: Gorgon Group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. [1]

CampaignEnterprise

C0005: Operation Spalax

Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical industries. The Operation Spalax threat actors distributed commodity malware and tools using generic phishing topics related to COVID-19, banking, and law enforcement action. Security researchers noted indicators of compromise and some infrastructure overlaps with other campaigns dating back to April 2018, including at least one separately attributed to APT-C-36, however identified enough differences to report this as separate, unattributed activity.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.4
Created
Modified
Raw hash
5a3832e1272fdff1...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.4Current bundle5a3832e1272f…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  2. [2]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  3. [3]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  4. [4]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  5. [5]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  6. [6]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  7. [7]
    VenereCiscoTalos_Gamaredon_Mar2025

    Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.

    Open source URL
  8. [8]
    LevelBlue Blind Eagle Proton66 JUN 2025

    Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.

    Open source URL
  9. [9]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  10. [10]
    Zscaler BlindEagle DEC 2025

    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

    Open source URL
  11. [11]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  12. [12]
    ESET Operation Spalax Jan 2021

    M. Porolli. (2021, January 21). Operation Spalax: Targeted malware attacks in Colombia. Retrieved September 16, 2022.

    Open source URL
  13. [13]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  14. [14]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  15. [15]
    Remcos

    (Citation: Riskiq Remcos Jan 2018)(Citation: Fortinet Remcos Feb 2017)(Citation: Talos Remcos Aug 2018)

  16. [16]
    Remcos

    (Citation: Riskiq Remcos Jan 2018)(Citation: Fortinet Remcos Feb 2017)(Citation: Talos Remcos Aug 2018)

  17. [17]
    Remcos

    (Citation: Riskiq Remcos Jan 2018)(Citation: Fortinet Remcos Feb 2017)(Citation: Talos Remcos Aug 2018)

  18. [18]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  19. [19]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  20. [20]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  21. [21]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  22. [22]
    mitre-attackS0332
    Open source URL
  23. [23]
    mitre-attackS0332
    Open source URL
  24. [24]
    mitre-attackS0332
    Open source URL
  25. [25]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  26. [26]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  27. [27]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  28. [28]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  29. [29]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  30. [30]
    MalwareBytes LazyScripter Feb 2021

    Jazi, H. (2021, February). LazyScripter: From Empire to double RAT. Retrieved November 17, 2024.

    Open source URL
  31. [31]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  32. [32]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  33. [33]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  34. [34]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  35. [35]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  36. [36]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  37. [37]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  38. [38]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  39. [39]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  40. [40]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  41. [41]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  42. [42]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  43. [43]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  44. [44]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  45. [45]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  46. [46]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  47. [47]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  48. [48]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  49. [49]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  50. [50]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  51. [51]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  52. [52]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  53. [53]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  54. [54]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  55. [55]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  56. [56]
    VenereCiscoTalos_Gamaredon_Mar2025

    Venere, G. (2025, March 28). Gamaredon campaign abuses LNK files to distribute Remcos backdoor. Retrieved July 23, 2025.

    Open source URL
  57. [57]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  58. [58]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  59. [59]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  60. [60]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  61. [61]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  62. [62]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  63. [63]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  64. [64]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  65. [65]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  66. [66]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  67. [67]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  68. [68]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  69. [69]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  70. [70]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  71. [71]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  72. [72]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  73. [73]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  74. [74]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  75. [75]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  76. [76]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  77. [77]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  78. [78]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  79. [79]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  80. [80]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  81. [81]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  82. [82]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  83. [83]
    LevelBlue Blind Eagle Proton66 JUN 2025

    Melnyk, S. (2025, June 27). Tracing Blind Eagle to Proton66. Retrieved April 16, 2026.

    Open source URL
  84. [84]
    Recorded Future TAG-144 AUG 2025

    Insikt Group. (2025, August 26). TAG-144’s Persistent Grip on South American Organizations. Retrieved April 16, 2026.

    Open source URL
  85. [85]
    Zscaler BlindEagle DEC 2025

    Pellegrino, G. (2025, December 16). BlindEagle Targets Colombian Government Agency with Caminho and DCRAT. Retrieved April 16, 2026.

    Open source URL
  86. [86]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  87. [87]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  88. [88]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  89. [89]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  90. [90]
    Unit 42 Gorgon Group Aug 2018

    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

    Open source URL
  91. [91]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  92. [92]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
  93. [93]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  94. [94]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  95. [95]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  96. [96]
    Talos Remcos Aug 2018

    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

    Open source URL
  97. [97]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  98. [98]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  99. [99]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  100. [100]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  101. [101]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  102. [102]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  103. [103]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  104. [104]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  105. [105]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  106. [106]
    Riskiq Remcos Jan 2018

    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

    Open source URL
  107. [107]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  108. [108]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  109. [109]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  110. [110]
    Fortinet Remcos Feb 2017

    Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

    Open source URL
  111. [111]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  112. [112]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  113. [113]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  114. [114]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  115. [115]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  116. [116]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  117. [117]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  118. [118]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  119. [119]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  120. [120]
    Check Point Blind Eagle MAR 2025

    Check Point Research. (2025, March 10). Blind Eagle: …And Justice for All. Retrieved April 16, 2026.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.