RemcosRATt malware family
RemcosRATt is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-03. Observed ATT&CK techniques include T1105.
Corpus statistics
- Publicly analyzed samples: 2
- First seen: 2026-07-29
- Last seen: 2026-08-03
- Verdicts: malicious 2
- File types: script 2
ATT&CK techniques used by RemcosRATt
- T1105 - 1 sample
Recent RemcosRATt samples
- a05e47692520185c1d3b5b0bb72b6a4b954064d2e28af22c5dad24fb2b924743.bin - malicious (2026-08-03)
- 3dbc051e39388c63bf4b1c35cd54ccc62745464feae42cf8755d57c401ecf5ba.js - malicious (2026-07-29)
Frequently asked about RemcosRATt
- What is RemcosRATt?
- RemcosRATt is a malware family tracked by MalwareAnalyzer by Cyble across 2 publicly analyzed samples. First seen 2026-07-29, most recently 2026-08-03. Observed ATT&CK techniques include T1105.
- How many RemcosRATt samples have been analyzed?
- MalwareAnalyzer by Cyble holds 2 publicly analyzed samples attributed to RemcosRATt, first seen 2026-07-29 and most recently 2026-08-03. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does RemcosRATt use?
- Across our RemcosRATt samples the most frequently observed techniques are T1105 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does RemcosRATt use?
- RemcosRATt samples in this corpus are distributed as script (2).
- Is RemcosRATt malicious?
- 2 of 2 analyzed RemcosRATt samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends