Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Remcos RAT C2 Activity Mapped Along with The Ports Used for Communications

Remcos RAT C2 Activity Mapped Along with The Ports Used for Communications

Posted on November 18, 2025November 18, 2025 By CWS

Remcos, a business distant entry instrument distributed by Breaking-Safety and marketed as administrative software program, has change into a severe menace within the cybersecurity panorama.

Developed within the mid-2010s, this malware permits attackers to execute distant instructions, steal information, seize screens, log keystrokes, and acquire person credentials by command-and-control servers utilizing HTTP or HTTPS channels.

Regardless of being positioned as professional software program with each free and paid variations, unauthorized copies are actively used within the wild for knowledge theft and unauthorized system entry.

The malware spreads by e mail campaigns containing malicious attachments and information hosted on compromised web sites.

Attackers additionally use specialised loaders akin to GuLoader and Reverse Loader to ship Remcos as a second-stage payload, permitting them to bypass preliminary detection methods.

As soon as put in, the malware establishes persistence and maintains steady communication with its management infrastructure, making a dependable backdoor for ongoing assaults.

Censys safety analysts famous that between October 14 and November 14, 2025, they constantly tracked over 150 lively Remcos command-and-control servers worldwide.

Infrastructure

This substantial infrastructure demonstrates the instrument’s widespread adoption amongst menace actors.

The servers sometimes operated on port 2404, the default alternative for Remcos, with extra exercise noticed on ports 5000, 5060, 5061, 8268, and 8808, exhibiting operators’ flexibility in deployment methods.

Remcos persistence configuration (Supply – Censys)

Understanding C2 Communication Networks reveals how Remcos maintains management. The malware communicates by HTTP and HTTPS protocols on predictable ports, with community site visitors continuously containing encoded POST requests and strange TLS configurations that create distinctive patterns.

Operators sometimes reuse certificates throughout a number of servers, make use of template-based setups, and leverage cheap internet hosting suppliers like COLOCROSSING, RAILNET, and CONTABO throughout america, Netherlands, Germany, and different international locations.

This infrastructure sample permits community defenders to establish and block communications at detection factors.

The detected persistence mechanisms embrace Scheduled Duties and Registry Run-key entries, permitting attackers to take care of entry even after system restarts.

This mix of command execution, file switch capabilities, and resilient persistence makes Remcos notably harmful for organizations with weak safety controls, requiring quick community monitoring and endpoint detection measures.

Observe us on Google Information, LinkedIn, and X to Get Extra Immediate Updates, Set CSN as a Most popular Supply in Google.

Cyber Security News Tags:Activity, Communications, Mapped, Ports, RAT, Remcos

Post navigation

Previous Post: Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities
Next Post: Authorities Seized Thousands of Servers from Rogue Hosting Company Used to Fuel Cyberattacks

Related Posts

Christmas Phishing Surge Chains Docusign Spoofing with Identity Theft Questionnaires Christmas Phishing Surge Chains Docusign Spoofing with Identity Theft Questionnaires Cyber Security News
Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects Threat Actors Leverage JSON Storage Services to Host and Deliver Malware Via Trojanized Code Projects Cyber Security News
Dutch Police Break Up €100 Million Fraud Network Dutch Police Break Up €100 Million Fraud Network Cyber Security News
PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild Cyber Security News
New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users New Phishing Kit As-a-service Attacking Google, Microsoft, and Okta Users Cyber Security News
Hackers Infiltrated Maven Central Masquerading as a Legitimate Jackson JSON Library Hackers Infiltrated Maven Central Masquerading as a Legitimate Jackson JSON Library Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks
  • WhatsApp Introduces Scam Alert to Enhance Security
  • Enterprise Security Shows Strength at Edge, Weakness Within

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark