Remcos RAT Analysis: How the Windows Remote Access Trojan Operates

Umut Bayram | 9 MIN READ

| June 30, 2026

Key Takeaways

  • Remcos RAT is a Windows remote access trojan first introduced in 2016 by Breaking Security as a remote administration product.
  • Once deployed, Remcos hands an operator near-complete control, enabling command execution, credential theft, and silent recording of user activity.
  • Remcos combines defense evasion via process injection, privilege escalation through a COM-based UAC bypass, and multi-layered registry and watchdog persistence.
  • Its surveillance toolkit includes keylogging, periodic screenshots, audio recording, an optional webcam module, and browser credential and cookie wiping.
  • The Picus Security Validation Platform simulates Remcos RAT attacks, letting organizations test security controls against this threat within minutes.

Remcos (Remote Control and Surveillance) is a Windows remote access trojan (RAT) that was first introduced in 2016 by the company Breaking Security, which marketed it as a legitimate remote administration product. Since then, it has been widely adopted by threat actors and has become one of the most prevalent commodity RATs in the wild.

Once deployed, Remcos hands an operator near-complete control over the infected machine. It combines defense evasion through process injection, privilege escalation via a COM-based UAC bypass, and multi-layered persistence using registry Run keys and a watchdog process. On top of this, it offers an extensive surveillance and data-theft toolkit, including keylogging, periodic screenshots, audio and webcam recording, and a rich set of command-and-control capabilities.

In this blog, we explain how Remcos RAT operates at each stage of its execution flow, and show how Picus validates your security controls against this threat.

What Is Remcos RAT?

Remcos RAT is a Windows remote access trojan that gives an operator near-complete remote control over an infected machine, including the ability to run commands, steal credentials, and silently record user activity.

It originally began life as a commercial remote administration tool but has since been widely adopted by threat actors targeting practically every sector.

Remcos is packed with offensive functionality, including:

  • Defense evasion through process injection and process masquerading.
  • Privilege escalation via a COM-based UAC bypass.
  • Persistence through multiple registry Run keys and a watchdog process.
  • Surveillance via keylogging, periodic screenshots, audio recording, and an optional webcam module.
  • Credential and data theft using helper utilities pulled from the C2.
  • Remote administration through a rich set of C2 commands, including a live shell, file management, and registry editing.

Is Remcos RAT a Virus or a Legitimate Tool?

Remcos occupies a gray area. It is marketed as a legitimate remote administration product [4], yet the same feature set, when deployed without consent, makes it a full-featured spyware and remote control trojan.

Once it is installed silently, hidden on disk, and used to exfiltrate keystrokes and credentials, it functions as malware regardless of its commercial framing.

How Does Remcos RAT Work?

Remcos works by decrypting an embedded configuration, optionally elevating its privileges and disabling User Account Control (UAC), installing itself and establishing persistence, injecting into a trusted process, starting its recording threads, and finally connecting to its C2 to await commands.

The subsections below follow that execution flow in order.

Loading and Decrypting the Configuration

Remcos stores its configuration as an RC4-encrypted blob inside a PE resource named SETTINGS. At startup, the malware locates and loads this encrypted blob from its own resource section before doing anything else [1]:

// Layout of the encrypted configuration blob inside the SETTINGS resource.

// The first byte tells you how long the RC4 key is, the key follows, and everything after that is the encrypted configuration data.

struct ctf::EncryptedConfiguration

{

uint8_t key_size; // length of the RC4 key in bytes

uint8_t key[key_size]; // the RC4 key

uint8_t data; // start of the encrypted configuration bytes

};

Once decrypted, the plaintext configuration is one long string that the malware splits into an internal array of fields. The delimiter between fields is the byte sequence "\x7c\x1f\x1e\x1e\x7c". Each resulting element corresponds to a numbered configuration field, which is how every later capability decides whether to run and where to write its output.

UAC Bypass and Disabling UAC

If the UAC bypass flag is set in configuration, Remcos tries to elevate itself to administrator using a well-known COM-based trick.

First, it disguises its own process. It edits the Process Environment Block (PEB) so the process looks like explorer.exe instead of the malware, and it saves the real values so it can put them back later.

Then it performs the actual bypass in three short steps:

  1. It calls the CoGetObject API with the special Elevation:Administrator!new: moniker, along with the CMSTPLUA CLSID and the ICMLuaUtil interface. This hands back a COM object that already runs with admin rights.
  2. It calls that object's ShellExec() method to launch a fresh copy of itself with administrator privileges.
  3. The original (non-admin) process then exits.

Separately, if the disable-UAC flag is set, Remcos turns UAC off in the registry by running the below command [1]:

:: Remcos uses the built-in reg.exe to flip EnableLUA to 0, disabling UAC prompts.

%WinDir%\System32\reg.exe ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f

Installation and Persistence

When the install flag is enabled in the config, Remcos copies itself onto the host.

The installation path is built from three configuration values: the install parent directory, the install directory, and the install filename. The binary is written to {install_parent_directory}\{install_directory}\{install_filename}.

After copying itself, Remcos establishes persistence in the registry depending on which flags are enabled:

  • HKCU Run key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
  • HKLM Run key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
  • HKLM Policies Explorer Run key: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

The Watchdog (Process-Level Persistence)

The registry Run keys keep Remcos alive across reboots, but the watchdog keeps it alive during a session: it is a second persistence layer that guards the running process.

If the watchdog flag is enabled in the config, Remcos starts a watchdog to keep itself running. The watchdog works by launching a new process, injecting Remcos into it, and monitoring the main process.

If the main process is terminated, the watchdog restarts it, and the main process can likewise restart the watchdog, so killing just one of the two is not enough to stop the malware.

The watchdog host process is chosen from a hardcoded list, picking the first one for which process creation and injection succeed:

# Hardcoded processes for watchdog host

svchost.exe

rmclient.exe

fsutil.exe

Spying and Data Theft Features

Remcos ships with a broad surveillance and control toolkit. Each capability is gated by its own configuration flag. The standout points for each are below.

Keylogging

Captures keystrokes with a low-level keyboard hook (SetWindowsHookExA + WH_KEYBOARD_LL) [2]. There are two modes: log everything, or log only while a targeted window is in the foreground. Logs can be RC4-encrypted.

An online variant streams keystrokes live to the C2 instead of writing to disk [3].

Browser Credential and Cookie Wiping

On startup, Remcos deletes saved logins and cookies from Internet Explorer, Firefox, and Chrome. This forces victims to re-authenticate and allows the attacker to capture plain-text credentials using keylogging capability.

Screenshot Capture

Grabs the screen with CreateCompatibleBitmap and BitBlt, optionally drawing the mouse cursor.

Audio Recording

Records the microphone through the Windows Wave* API in fixed-length chunks, saving timestamped .wav files to a configured folder.

Webcam Capture

The webcam module is a DLL pushed from the C2 at runtime, exposing OpenCamera, CloseCamera, GetFrame, and FreeFrame exports [3]. Because the webcam code is never stored on disk, static analysis of the dropped sample shows no webcam feature at all.

Command and Control Communication

Remcos tries each entry in its C2 list until one answers, optionally over TLS using certificates carried in the configuration.

Traffic rides a custom binary protocol with a fixed magic header (\x24\x04\xff\x00, or 0xFF0424), a 4-byte length, a 4-byte command id, and delimited data fields using the delimiter "\x1e\x1e\x1f|".

Below, notable commands are listed:

  • ListInstalledApplications: Remcos enumerates the Software\Microsoft\Windows\CurrentVersion\Uninstall registry key and, for each subkey, reads the DisplayName, Publisher, DisplayVersion, InstallLocation, InstallDate, and UninstallString values to build a software inventory of the host.
  • GetHostGeolocation: Remcos queries the public geoplugin.net service and uploads the returned JSON directly, giving the operator the victim's approximate location.
  • StealPasswords: Credential theft is carried out with three helper utilities pulled from the C2 and injected into a freshly created process. They are invoked with a /sext parameter that writes output to a randomly named file in the install folder. After the output is read and uploaded, the file is deleted. An additional DLL exporting FoxMailRecovery can also be supplied from the C2 to dump FoxMail data.
  • DumpBrowserHistoryUsingNirsoft: Similar to credential theft, this pulls a helper binary from the C2 to extract browser history.

How Picus Simulates Remcos RAT Attacks?

We strongly suggest simulating Remcos RAT Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.

Picus Threat Library includes the following threats for the Remcos RAT Attacks:

Threat ID

Threat Name

Attack Module

46613

Remcos Loader Download Threat

Network Infiltration

37854

Remcos Loader Email Threat

E-mail Infiltration

86397

Remcos RAT Download Threat - 2

Network Infiltration

96030

Remcos RAT Email Threat - 2

E-mail Infiltration

97606

Remcos RAT Download Threat - 1

Network Infiltration

51911

Remcos RAT Email Threat - 1

E-mail Infiltration

44623

Remcos Malware Downloader Download Threat

Network Infiltration

27648

Remcos Malware Downloader Email Threat

E-mail Infiltration

76426

Remcos RAT Campaign

Windows Endpoint

30196

Remcos Malware Dropper Download Threat

Network Infiltration

51560

Remcos Malware Dropper Email Threat

E-mail Infiltration

45014

Remcos Downloader Download Threat

Network Infiltration

73493

Remcos Downloader Email Threat

E-mail Infiltration

59698

RemcosRAT Trojan Download Threat

Network Infiltration

83736

RemcosRAT Trojan Email Threat

E-mail Infiltration

67632

RemcosRAT Loader Download Threat

Network Infiltration

Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.

References

[1] C. François and S. Bousseaden, “Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One.” Accessed: Jun. 25, 2026. [Online]. Available: https://www.elastic.co/security-labs/dissecting-remcos-rat-part-one

[2] C. François and S. Bousseaden, “Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Two.” Accessed: Jun. 25, 2026. [Online]. Available: https://www.elastic.co/security-labs/dissecting-remcos-rat-part-two

[3] C. François and S. Bousseaden, “Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three.” Accessed: Jun. 25, 2026. [Online]. Available: https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three

[4] F. Fkie, “Remcos (Malware Family).” Accessed: Jun. 25, 2026. [Online]. Available: https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos

 

 
Remcos (Remote Control and Surveillance) is a Windows remote access trojan that gives an operator near-complete control over an infected machine. It can run commands, steal credentials, and silently record user activity. Originally introduced in 2016 by Breaking Security as a legitimate remote administration product, it has since become one of the most prevalent commodity RATs.
Remcos occupies a gray area. It is marketed as a legitimate remote administration product, yet the same feature set, when deployed without consent, makes it a full-featured spyware and remote control trojan. Once installed silently, hidden on disk, and used to exfiltrate keystrokes and credentials, it functions as malware regardless of its commercial framing.
Remcos decrypts an embedded RC4-encrypted configuration, optionally elevates privileges and disables UAC, installs itself and establishes persistence, injects into a trusted process, starts its recording threads, and finally connects to its command-and-control server to await commands. Each capability is gated by its own configuration flag that decides whether the feature runs.
Remcos ships with a broad surveillance toolkit, each gated by a configuration flag. It includes keylogging via a low-level keyboard hook, screenshot capture, microphone audio recording, and an optional webcam module pushed from the command-and-control server. It also wipes browser credentials and cookies to force re-authentication, enabling capture of plain-text credentials through keylogging.
If the UAC bypass flag is set, Remcos disguises its process as explorer.exe by editing the Process Environment Block, then uses a COM-based trick. It calls CoGetObject with the Elevation:Administrator!new: moniker, the CMSTPLUA CLSID, and the ICMLuaUtil interface, then calls ShellExec() to relaunch itself with admin rights before the original process exits.
The Picus Security Validation Platform simulates Remcos RAT attacks to test the effectiveness of security controls against real-life cyber attacks. The Picus Threat Library includes multiple Remcos threats across network and email infiltration and Windows endpoint modules. Defenses can also be tested against hundreds of other malware variants within minutes through a 14-day free trial.

Table of Contents

Ready to start? Request a demo