FILEMembers
FILE

Remcos RAT Sample Stalls Sandboxes, Checks for Debuggers

A 92KB unsigned dropper flagged by 64 of 74 antivirus engines runs the commodity Remcos RAT, with three independent sandboxes unanimously calling it malicious. The sample builds in sandbox-timing and anti-debug checks that let a well-known RAT slip past first-tier automated triage.

Sep 19, 2026, 06:42 (UTC+9)Last seenSep 19, 2026Severity77ByCTX TeamActorGorgon GroupSubaatIOC6MITRE11

A 92-kilobyte Windows executable now flagged by 64 of 74 antivirus engines carries one of the most heavily fingerprinted commodity RATs in current circulation — and it does so with a textbook anti-analysis playbook baked in before it ever reveals its payload. The dropper, tracked here as d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867, is unsigned, packed with PEiD, and — according to three independent sandboxes that returned a unanimous malicious verdict — runs as Remcos, the…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence