Remcos RAT Analysis: How the Windows Remote Access Trojan Operates
| June 30, 2026
Key Takeaways
- Remcos RAT is a Windows remote access trojan first introduced in 2016 by Breaking Security as a remote administration product.
- Once deployed, Remcos hands an operator near-complete control, enabling command execution, credential theft, and silent recording of user activity.
- Remcos combines defense evasion via process injection, privilege escalation through a COM-based UAC bypass, and multi-layered registry and watchdog persistence.
- Its surveillance toolkit includes keylogging, periodic screenshots, audio recording, an optional webcam module, and browser credential and cookie wiping.
- The Picus Security Validation Platform simulates Remcos RAT attacks, letting organizations test security controls against this threat within minutes.
Remcos (Remote Control and Surveillance) is a Windows remote access trojan (RAT) that was first introduced in 2016 by the company Breaking Security, which marketed it as a legitimate remote administration product. Since then, it has been widely adopted by threat actors and has become one of the most prevalent commodity RATs in the wild.
Once deployed, Remcos hands an operator near-complete control over the infected machine. It combines defense evasion through process injection, privilege escalation via a COM-based UAC bypass, and multi-layered persistence using registry Run keys and a watchdog process. On top of this, it offers an extensive surveillance and data-theft toolkit, including keylogging, periodic screenshots, audio and webcam recording, and a rich set of command-and-control capabilities.
In this blog, we explain how Remcos RAT operates at each stage of its execution flow, and show how Picus validates your security controls against this threat.
What Is Remcos RAT?
Remcos RAT is a Windows remote access trojan that gives an operator near-complete remote control over an infected machine, including the ability to run commands, steal credentials, and silently record user activity.
It originally began life as a commercial remote administration tool but has since been widely adopted by threat actors targeting practically every sector.
Remcos is packed with offensive functionality, including:
- Defense evasion through process injection and process masquerading.
- Privilege escalation via a COM-based UAC bypass.
- Persistence through multiple registry Run keys and a watchdog process.
- Surveillance via keylogging, periodic screenshots, audio recording, and an optional webcam module.
- Credential and data theft using helper utilities pulled from the C2.
- Remote administration through a rich set of C2 commands, including a live shell, file management, and registry editing.
Is Remcos RAT a Virus or a Legitimate Tool?
Remcos occupies a gray area. It is marketed as a legitimate remote administration product [4], yet the same feature set, when deployed without consent, makes it a full-featured spyware and remote control trojan.
Once it is installed silently, hidden on disk, and used to exfiltrate keystrokes and credentials, it functions as malware regardless of its commercial framing.
How Does Remcos RAT Work?
Remcos works by decrypting an embedded configuration, optionally elevating its privileges and disabling User Account Control (UAC), installing itself and establishing persistence, injecting into a trusted process, starting its recording threads, and finally connecting to its C2 to await commands.
The subsections below follow that execution flow in order.
Loading and Decrypting the Configuration
Remcos stores its configuration as an RC4-encrypted blob inside a PE resource named SETTINGS. At startup, the malware locates and loads this encrypted blob from its own resource section before doing anything else [1]:
|
// Layout of the encrypted configuration blob inside the SETTINGS resource. // The first byte tells you how long the RC4 key is, the key follows, and everything after that is the encrypted configuration data. struct ctf::EncryptedConfiguration { uint8_t key_size; // length of the RC4 key in bytes uint8_t key[key_size]; // the RC4 key uint8_t data; // start of the encrypted configuration bytes }; |
Once decrypted, the plaintext configuration is one long string that the malware splits into an internal array of fields. The delimiter between fields is the byte sequence "\x7c\x1f\x1e\x1e\x7c". Each resulting element corresponds to a numbered configuration field, which is how every later capability decides whether to run and where to write its output.
UAC Bypass and Disabling UAC
If the UAC bypass flag is set in configuration, Remcos tries to elevate itself to administrator using a well-known COM-based trick.
First, it disguises its own process. It edits the Process Environment Block (PEB) so the process looks like explorer.exe instead of the malware, and it saves the real values so it can put them back later.
Then it performs the actual bypass in three short steps:
- It calls the CoGetObject API with the special Elevation:Administrator!new: moniker, along with the CMSTPLUA CLSID and the ICMLuaUtil interface. This hands back a COM object that already runs with admin rights.
- It calls that object's ShellExec() method to launch a fresh copy of itself with administrator privileges.
- The original (non-admin) process then exits.
Separately, if the disable-UAC flag is set, Remcos turns UAC off in the registry by running the below command [1]:
|
:: Remcos uses the built-in reg.exe to flip EnableLUA to 0, disabling UAC prompts. |
Installation and Persistence
When the install flag is enabled in the config, Remcos copies itself onto the host.
The installation path is built from three configuration values: the install parent directory, the install directory, and the install filename. The binary is written to {install_parent_directory}\{install_directory}\{install_filename}.
After copying itself, Remcos establishes persistence in the registry depending on which flags are enabled:
- HKCU Run key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
- HKLM Run key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
- HKLM Policies Explorer Run key: HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\
The Watchdog (Process-Level Persistence)
The registry Run keys keep Remcos alive across reboots, but the watchdog keeps it alive during a session: it is a second persistence layer that guards the running process.
If the watchdog flag is enabled in the config, Remcos starts a watchdog to keep itself running. The watchdog works by launching a new process, injecting Remcos into it, and monitoring the main process.
If the main process is terminated, the watchdog restarts it, and the main process can likewise restart the watchdog, so killing just one of the two is not enough to stop the malware.
The watchdog host process is chosen from a hardcoded list, picking the first one for which process creation and injection succeed:
|
# Hardcoded processes for watchdog host svchost.exe rmclient.exe fsutil.exe |
Spying and Data Theft Features
Remcos ships with a broad surveillance and control toolkit. Each capability is gated by its own configuration flag. The standout points for each are below.
Keylogging
Captures keystrokes with a low-level keyboard hook (SetWindowsHookExA + WH_KEYBOARD_LL) [2]. There are two modes: log everything, or log only while a targeted window is in the foreground. Logs can be RC4-encrypted.
An online variant streams keystrokes live to the C2 instead of writing to disk [3].
Browser Credential and Cookie Wiping
On startup, Remcos deletes saved logins and cookies from Internet Explorer, Firefox, and Chrome. This forces victims to re-authenticate and allows the attacker to capture plain-text credentials using keylogging capability.
Screenshot Capture
Grabs the screen with CreateCompatibleBitmap and BitBlt, optionally drawing the mouse cursor.
Audio Recording
Records the microphone through the Windows Wave* API in fixed-length chunks, saving timestamped .wav files to a configured folder.
Webcam Capture
The webcam module is a DLL pushed from the C2 at runtime, exposing OpenCamera, CloseCamera, GetFrame, and FreeFrame exports [3]. Because the webcam code is never stored on disk, static analysis of the dropped sample shows no webcam feature at all.
Command and Control Communication
Remcos tries each entry in its C2 list until one answers, optionally over TLS using certificates carried in the configuration.
Traffic rides a custom binary protocol with a fixed magic header (\x24\x04\xff\x00, or 0xFF0424), a 4-byte length, a 4-byte command id, and delimited data fields using the delimiter "\x1e\x1e\x1f|".
Below, notable commands are listed:
- ListInstalledApplications: Remcos enumerates the Software\Microsoft\Windows\CurrentVersion\Uninstall registry key and, for each subkey, reads the DisplayName, Publisher, DisplayVersion, InstallLocation, InstallDate, and UninstallString values to build a software inventory of the host.
- GetHostGeolocation: Remcos queries the public geoplugin.net service and uploads the returned JSON directly, giving the operator the victim's approximate location.
- StealPasswords: Credential theft is carried out with three helper utilities pulled from the C2 and injected into a freshly created process. They are invoked with a /sext parameter that writes output to a randomly named file in the install folder. After the output is read and uploaded, the file is deleted. An additional DLL exporting FoxMailRecovery can also be supplied from the C2 to dump FoxMail data.
- DumpBrowserHistoryUsingNirsoft: Similar to credential theft, this pulls a helper binary from the C2 to extract browser history.
How Picus Simulates Remcos RAT Attacks?
We strongly suggest simulating Remcos RAT Attacks to test the effectiveness of your security controls against real-life cyber attacks using the Picus Platform. You can also test your defenses against hundreds of other malware variants, such as BRICKSTORM, VenomRAT, Chinotto, and Rustonotto, within minutes with a 14-day free trial of the Picus Platform.
Picus Threat Library includes the following threats for the Remcos RAT Attacks:
|
Threat ID |
Threat Name |
Attack Module |
|
46613 |
Remcos Loader Download Threat |
Network Infiltration |
|
37854 |
Remcos Loader Email Threat |
E-mail Infiltration |
|
86397 |
Remcos RAT Download Threat - 2 |
Network Infiltration |
|
96030 |
Remcos RAT Email Threat - 2 |
E-mail Infiltration |
|
97606 |
Remcos RAT Download Threat - 1 |
Network Infiltration |
|
51911 |
Remcos RAT Email Threat - 1 |
E-mail Infiltration |
|
44623 |
Remcos Malware Downloader Download Threat |
Network Infiltration |
|
27648 |
Remcos Malware Downloader Email Threat |
E-mail Infiltration |
|
76426 |
Remcos RAT Campaign |
Windows Endpoint |
|
30196 |
Remcos Malware Dropper Download Threat |
Network Infiltration |
|
51560 |
Remcos Malware Dropper Email Threat |
E-mail Infiltration |
|
45014 |
Remcos Downloader Download Threat |
Network Infiltration |
|
73493 |
Remcos Downloader Email Threat |
E-mail Infiltration |
|
59698 |
RemcosRAT Trojan Download Threat |
Network Infiltration |
|
83736 |
RemcosRAT Trojan Email Threat |
E-mail Infiltration |
|
67632 |
RemcosRAT Loader Download Threat |
Network Infiltration |
Start simulating emerging threats today and get actionable mitigation insights with a 14-day free trial of the Picus Platform.
References
[1] C. François and S. Bousseaden, “Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One.” Accessed: Jun. 25, 2026. [Online]. Available: https://www.elastic.co/security-labs/dissecting-remcos-rat-part-one
[2] C. François and S. Bousseaden, “Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Two.” Accessed: Jun. 25, 2026. [Online]. Available: https://www.elastic.co/security-labs/dissecting-remcos-rat-part-two
[3] C. François and S. Bousseaden, “Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three.” Accessed: Jun. 25, 2026. [Online]. Available: https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three
[4] F. Fkie, “Remcos (Malware Family).” Accessed: Jun. 25, 2026. [Online]. Available: https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
