
Old RemCom Hacktool Masks a Clean-Scoring WinSW Impostor
A RemCom-class remote-execution tool compiled in 2012 is still being resubmitted under randomized filenames as of July 2026, flagged by 46 of 75 engines. Alongside it in the same indicator set sits a 16.8MB binary impersonating the WinSW Windows Service Wrapper that clears all 77 scanning engines.
A remote-command-execution hacktool compiled on 2012-08-09 is still being resubmitted under randomized filenames as recently as July 2026, flagged by 46 of 75 engines and matched by three named YARA rules — and sitting in the same indicator set is a 16.8-megabyte binary posing as the open-source WinSW Windows Service Wrapper that clears every one of 77 antivirus engines outright.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read