Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →In a February 15, 2017 report, SecurityWeek said Fortinet researchers had observed Remcos in live attacks. Their analysis described a Remcos v1.7.3 Pro sample delivered through malicious Office documents and capable of remote surveillance, credential theft, and command execution. The report is a snapshot of that sample and period—not evidence of Remcos activity or detection coverage today.
What Remcos RAT was in the 2017 report
Remcos is described in the report as a remote access tool (RAT), software that lets an operator control or monitor a computer remotely. SecurityWeek’s Ionut Arghire reported that Remcos had appeared on hacking forums in 2016 and that Fortinet researchers had encountered it in live attacks by February 2017. The analyzed server component was based on Remcos v1.7.3 Pro, which the developer’s website reportedly said was released on January 23, 2017.
The report quoted Fortinet researchers: “More and more applications like Remcos are being released publicly, luring new perpetrators with their easy usage.” That observation concerned the availability and usability of tools at the time; it does not establish current Remcos prevalence.
How the reported attacks delivered and ran Remcos
The analyzed malicious Office documents were named Quotation.xls or Quotation.doc and were reportedly delivered by email. Their obfuscated macros called shell commands. Fortinet described use of Event Viewer (eventvwr.exe) in a User Account Control (UAC) bypass technique.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
The report also says the Remcos server component had its own UAC-bypass function and describes a routine that reverted a modified registry setting after elevation. These are observations about the 2017 sample, not a signature that applies to every Remcos version or current attack.
What the analyzed Remcos sample could do
The client interface reportedly included Connections, Automatic Tasks, Local Settings, Builder, Event Log, and About tabs. The Connections tab showed active connections and system information, and offered the operator actions including:
- Taking screenshots and searching files.
- Viewing processes and executing commands.
- Logging keystrokes and stealing passwords.
- Accessing a webcam and microphone.
- Downloading and executing code.
Automatic Tasks
Fortinet highlighted an Automatic Tasks feature that could be configured to run functions automatically after a connection, without a manual command from the client. Researchers characterized this as enabling an “infiltrate-exfiltrate-exit” sequence. The report does not say how often attackers used this feature; its presence in the client is not proof that it was used in every attack.
Settings and packing reported for the sample
The Local Settings tab allowed configuration of ports and passwords. The report says the same password was used for authentication and as a key for RC4 traffic encryption. It also says the analyzed sample used UPX and MPRESS1 packing, with an additional custom packer layered over MPRESS1. These details describe the sample examined in 2017, not necessarily later versions.
What the report does—and does not—establish
SecurityWeek reported a license price range of $58 to $389 at the time, varying by license period and number of “masters” or clients. This is a historical figure, not a current price. The report provides no infection count, victim count, prevalence statistic, or detection-rate measurement.
It therefore cannot answer how common Remcos is now, what current campaigns may be doing, what capabilities later versions have, or which present-day security products detect it. Those questions require newer threat reporting and current, product-specific evidence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Source
SecurityWeek, Ionut Arghire, “Easy-to-Use Remcos RAT Spotted in Live Attacks,” February 15, 2017.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

