APTMembers
APT

Old RemCom Hacktool Masks a Clean-Scoring WinSW Impostor

A RemCom-class remote-execution tool compiled in 2012 is still being resubmitted under randomized filenames as of July 2026, flagged by 46 of 75 engines. Alongside it in the same indicator set sits a 16.8MB binary impersonating the WinSW Windows Service Wrapper that clears all 77 scanning engines.

Aug 9, 2026, 10:45 (UTC+9)Last seenAug 9, 2026Severity100ByCTX TeamActorCactusCactus Ransomware GroupIOC15MITRE20

A remote-command-execution hacktool compiled on 2012-08-09 is still being resubmitted under randomized filenames as recently as July 2026, flagged by 46 of 75 engines and matched by three named YARA rules — and sitting in the same indicator set is a 16.8-megabyte binary posing as the open-source WinSW Windows Service Wrapper that clears every one of 77 antivirus engines outright.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence