RemcosRAT samples seen in MalwareBazaar
Attackers use Remcos to control infected Windows devices remotely and steal information. It is also marketed as a remote-management tool.
Background
CISA and ACSC's 2022 overview describes malicious Remcos attachments in phishing campaigns. An unexpected installation needs investigation even though the tool is sold commercially.
What to do
If your antivirus reports Remcos, open its detection history to see whether the threat was blocked, quarantined or still needs action. If you use Microsoft Defender on Windows, open Windows Security > Virus & threat protection > Protection history. If the status is Threat found - action needed, follow Defender's recommended action. Threat blocked means Defender reports it removed that threat. Keep a quarantined file quarantined; do not choose Allow on device.
On a work device, ask IT whether the Remcos installation is authorized. If it is unauthorized or security software reports an active infection, disconnect the device from the network and contact IT. For a personal device, follow your antivirus removal instructions. If it ran, use a clean device to secure accounts used there because remote access can expose passwords and files.
Feed records
MalwareBazaar listed 1 file sample tagged RemcosRAT among the 100 uploads checked for this report. This is a count of feed entries, not infected devices. The background above was checked on 2026-09-08; the feed records have their own observation dates.