Remcos

MITRE
Malware Type:
Tool
First seen:
Unknown
Last seen:
Unknown
Details:

[Remcos](https://attack.mitre.org/software/S0332) is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. [Remcos](https://attack.mitre.org/software/S0332) has been observed being used in malware campaigns.(Citation: Riskiq Remcos Jan 2018)(Citation: Talos Remcos Aug 2018)

Associated Techniques (16)
ID ATT&CK Tactics
T1027 Obfuscated Files or Information -
T1055 Process Injection -
T1056.001 Keylogging -
T1059.003 Windows Command Shell -
T1059.006 Python -
T1083 File and Directory Discovery -
T1090 Proxy -
T1105 Ingress Tool Transfer -
T1112 Modify Registry -
T1113 Screen Capture -
T1115 Clipboard Data -
T1123 Audio Capture -
T1125 Video Capture -
T1497.001 System Checks -
T1547.001 Registry Run Keys / Startup Folder -
Metadata
ID: 738
Created: 13/01/2026 17:48
Updated: 21/04/2026 16:00