ficus.in: picture files hiding the Remcos remote access trojan, and what to do if a script fetched them

ficus.in is a web address, registered since 2010, that URLhaus lists ten times between 15 September and 1 October 2026 for picture files (img_*.png in its img folder) tagged stego, nine of them tagged RemcosRAT, a remote access trojan for Windows. A picture like that does not infect you when you look at it; it is a later stage that a script already running on a PC fetches.

If you only visited the site or saw the name in a log, nothing is proven. If something on your PC may have fetched these files, treat the PC as watched: change your passwords from another device, then scan and clean or reset Windows.

Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

If a script, loader or program that downloads picture files from ficus.in keeps coming back after uninstalling, a scan can find what reinstalls it.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove ficus.in (Remcos RAT, stego PNG files) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of ten URLhaus entries for ficus.in, files img_*.png in the img folder, all offline, tagged stego, nine also tagged RemcosRAT and rat
The ten URLhaus entries for ficus.in that we read on 8 October 2026. Our check was a plain request from our server, not a browser visit, so this table of reports is the main evidence.

Ficus.in (Remcos RAT, stego PNG files): summary

TypeA web folder that served PNG files tagged stego; nine of ten also tagged RemcosRAT and rat (a remote access trojan for Windows)
RiskHigh if a script on your PC fetched its files: keystrokes, passwords, screen, camera, microphone and files may be taken. Low if you only saw the name or visited the site
SymptomsOften none. A Run key entry you did not make, caspol.exe or msbuild.exe running with no reason, or a Defender detection naming Remcos
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure
Our check (8 October 2026)One plain request: a redirect to https://www.ficus.in/, served by nginx. It clears nothing; the danger rating comes from URLhaus
Running since / first seenDomain registered 18 April 2010; first picture file reported 15 September 2026, last 1 October 2026; all ten offline on 8 October 2026
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo detection name is known for the files on this site, because we did not open them. Microsoft detects the family as Backdoor:Win32/Remcos
NameFicus.in
Domain registered18 April 2010
Evidence10 write-ups by security sites; details still limited
First seen15 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked8 October 2026

Facts checked on 8 October 2026 against the URLhaus data for ficus.in held in our database, RDAP, one plain request from our server (no browser), and published pages by MITRE ATT&CK, Microsoft and Seqrite Labs. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What ficus.in is, and what we know about it

ficus.in is not a program on your PC. It is a web address, registered in India since 2010, that the abuse.ch project URLhaus lists ten times between 15 September and 1 October 2026 for picture files in a folder called img. Nine are tagged RemcosRAT, a remote access trojan for Windows, and all ten are tagged stego. We found no public write-up of this address, so this page rests on URLhaus, our own plain request and what Microsoft, MITRE and Seqrite publish.

An old domain with a normal web address that suddenly serves malware pictures from an image folder usually means one of two things: the site was broken into and a stranger uses its folder as free storage, or the domain changed hands.

We cannot tell which from the outside. Either way, the files were there, and either way the advice for a visitor and for a PC owner is the same.

  1. 1

    What URLhaus lists

    Ten file addresses under hxxps://ficus[.]in/img/, each named img_ followed by six digits and the ending .png. The first was added on 15 September 2026, then one on 23 September, one on 24 September, five on 30 September and two on 1 October. All carry the threat label malware_download and the reporter abuse_ch. All ten were marked offline in our copy of the data on 8 October 2026.

  2. 2

    What the tags mean

    stego is short for steganography: data hidden inside another file, here a picture. RemcosRAT names Remcos, a remote control tool sold by a company called Breaking Security that criminals use as a trojan. rat means remote access trojan. Nine files carry all three tags; img_011624.png, added on 30 September, is tagged only stego.

  3. 3

    What we could not confirm

    We did not download any of the pictures, so we cannot tell you what is inside them, which Remcos build they carry or where it reports to. URLhaus shows tags, not a full analysis. We also do not know which program or email makes a victim's PC ask for these files. That first step is not visible from the server.

  4. 4

    What this means for you

    If you only visited the ficus.in website, or saw its name in a log or a warning, you are not infected by that alone. The risk is for a Windows PC where a script was already running and went to fetch one of these pictures. A person browsing the site has no reason to request a file named img_220032.png directly.

Kind of threat
A web folder that served PNG files tagged stego; nine of ten tagged RemcosRAT, a remote access trojan for Windows
Where the files were
hxxps://ficus[.]in/img/img_NNNNNN.png, on the normal secure web port
Domain registered
18 April 2010, registrar Endurance International Group India Private Limited, status client transfer prohibited (RDAP, read 8 October 2026)
URLhaus entries
10 file addresses, added 15 September to 1 October 2026; all 10 offline when we read the data on 8 October 2026
Delivery trick
Steganography: code hidden in picture files so the download looks like an image. The entry step on the victim's PC is not known
Platform
Windows. MITRE lists Remcos for Windows only. Nothing we read says these pictures affect Mac, iPhone or Android

What ficus.in (Remcos RAT, stego PNG files) does on an infected PC

What we checked on 8 October 2026, and what we could not

We sent one plain request to ficus.in from our server on 8 October 2026: no browser, no clicks, no file downloads. The server answered with a redirect (HTTP 301) to https://www.ficus.in/ and named its web server software as nginx/1.29.8. That is all a plain request shows, and it clears nothing.

Our check, 8 October 2026

  • The domain answersHTTP 301, a permanent redirect to https://www.ficus.in/. The server header says nginx/1.29.8. This tells us the domain still has a working web server; it does not tell us what the site shows or whether it is clean.
  • What a plain request cannot seeWe did not load the page in a browser, did not run its scripts and did not request the img folder. A hacked site can look normal on its front page while a folder deeper down holds malware.
  • Notification requestOur tool found no mention of a browser notification request in the answer. With a redirect and no page body, there was little to see.
  • URLhaus listingTen picture files in /img/ tagged stego; nine tagged RemcosRAT and rat; reported from 15 September to 1 October 2026.
  • Files offline nowURLhaus marks all ten addresses offline. That means they no longer answered when checked. It does not mean the site was cleaned or that new file names cannot appear.

Treat its img folder as a malware source The rating comes from the ten URLhaus reports and their tags, not from our request. The site itself may belong to a real business whose server was misused. Do not run anything that downloads files from this address, and if you own the site, read the section for site owners below.

What happened to ficus.in, from registration to our check

The domain is sixteen years old, and the reports all fall within about two weeks. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.

  1. 18 April 2010

    The domain is registered

    RDAP shows ficus.in registered on 18 April 2010 through Endurance International Group India Private Limited, with the status client transfer prohibited. A long history like this is typical of a real business site, not of a throwaway malware domain.

  2. 15 September 2026

    The first picture is reported

    At about 15:27 UTC abuse.ch adds img_214254.png, tagged RemcosRAT, rat and stego.

  3. 23 and 24 September 2026

    Two more files

    img_012405.png is added on 23 September at about 08:52 UTC and img_212442.png on 24 September at about 12:56 UTC, both with the same three tags.

  4. 30 September 2026

    Five files in one day

    img_220032.png at about 06:00 UTC, then img_221258.png, img_215413.png and img_220602.png between 12:38 and 12:42 UTC, all tagged RemcosRAT, rat and stego. img_011624.png follows at about 14:50 UTC, tagged only stego.

    Table of the ten URLhaus entries for ficus.in with date, file name, tags and offline status
    All ten URLhaus entries for ficus.in as we read them on 8 October 2026. The folder stays the same; the six digit file names change.
  5. 1 October 2026

    The last two reports

    img_210244.png and img_205551.png are added at about 16:12 UTC, both tagged RemcosRAT, rat and stego. This is the newest report we hold.

  6. 8 October 2026

    All offline, and our check

    All ten addresses are marked offline in the URLhaus data. Our plain request to the domain returns a redirect to the www address, served by nginx.

What the pattern suggests, and what it does not: new file names kept appearing in the same folder for more than two weeks, which looks like someone with ongoing write access to the folder rather than a single leftover file. That is our reading of the dates, not something any report says.

How a picture file can carry Remcos

A picture that hides code cannot hurt you by being opened or looked at. It works only when a script that is already running reads the hidden part and starts it. We did not see the files on ficus.in; this is how Seqrite describes a campaign whose main payload was Remcos.

Five steps: a first file runs, it downloads a PNG, code is pulled out of the picture, Remcos starts inside a genuine Windows program, and someone takes control of the PC
The picture trick in five steps, as Seqrite and MITRE describe it. The entry step on a victim's PC is not something we saw for ficus.in.
  1. 1

    A phishing attachment opens

    Seqrite (17 March 2025) describes an Excel attachment that poses as a genuine file and abuses an old Office flaw, CVE-2017-0199, to request an .hta file from the internet. MITRE also lists spearphishing emails with Excel attachments as a way Remcos has spread.

  2. 2

    Scripts fetch the next piece

    In Seqrite's chain the .hta file holds VBScript that writes a batch file. The batch file downloads an obfuscated VBS script, and that script hides a base64 encoded PowerShell command. The PowerShell command is the part that downloads a picture.

  3. 3

    The picture holds a program

    Seqrite found picture files that hide base64 text between the markers <<BASE64 START>> and <<BASE64 END>>. The script searches the picture for those markers and decodes what lies between them into a loader. The picture still looks like an image to a filter that checks only file types.

  4. 4

    The loader hides Remcos in a trusted program

    Seqrite describes process hollowing: the loader starts caspol.exe or msbuild.exe from C:\Windows\SysWOW64, empties it and writes the malware into it. MITRE lists process injection for Remcos. In Task Manager the process then has a genuine Windows name.

  5. 5

    Remcos connects to its controller

    From then on a person elsewhere can use the PC. MITRE says Remcos encrypts its traffic with TLS and has used dynamic DNS addresses, so the connection does not stand out by its content.

Whether the pictures on ficus.in used the same markers, the same scripts or a different method is not known to us. The tags say only that something was hidden in them and that the hidden part was identified as Remcos.

What Remcos is

Remcos is sold openly as remote control and surveillance software by a company called Breaking Security, and criminals use it as a remote access trojan. The sources agree on what it can do; they differ in the details of each campaign.

Sources: MITRE ATT&CK S0332, Microsoft's Backdoor:Win32/Remcos entry and Seqrite Labs, all read 8 October 2026.
QuestionWhat the sources saySource
What is it?Closed source software marketed as remote control and surveillance software by Breaking Security, observed in malware campaignsMITRE ATT&CK S0332
Since when is it tracked?MITRE created its entry on 29 January 2019; Microsoft published its Backdoor:Win32/Remcos entry on 3 August 2018MITRE; Microsoft
What does it do?Keylogging, screenshots, webcam pictures, microphone recording, clipboard theft, file upload, download and deletion, remote commandsMITRE; Microsoft
How does it stay?It adds itself to the Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, so it starts at sign inMITRE
How does it hide?A built in UAC bypass, process injection, hidden windows, hidden files, encrypted settings and checks for Sandboxie and VMwareMITRE
Who uses it?MITRE names Gorgon Group, Gamaredon Group, LazyScripter and APT-C-36, and Operation SpalaxMITRE
What comes with it?Seqrite found Remcos as the main payload of a picture campaign that also delivered AsyncRAT, DcRAT, AgentTesla and VIPKeyLoggerSeqrite
Which build is on ficus.in?Not known. URLhaus gives only the tag RemcosRAT; we did not open the filesNot available

What ficus.in (Remcos RAT, stego PNG files) can steal or download

What Remcos can take from a Windows PC

A remote access trojan gives a stranger a seat at your computer, so the list below is what such a person can do, not what every build does on its own. Each item is named by MITRE or Microsoft.

Reported as possible

  • Every key you type
  • Screenshots of your screen
  • Webcam pictures
  • Microphone recordings
  • What you copy to the clipboard
  • Passwords
  • Files searched, uploaded and downloaded
  • Files deleted
  • Programs started or stopped
  • Your PC used as a SOCKS5 proxy
  • Saved browser cookies and logins wiped
Sources: MITRE ATT&CK S0332 (modified 23 April 2026) and Microsoft's Backdoor:Win32/Remcos entry, read 8 October 2026.
DataDetailSource
KeystrokesKeylogging, started and stopped on commandMITRE; Microsoft
ScreenAutomated screenshotsMITRE; Microsoft
Camera and microphoneWebcam pictures and audio recordingMITRE; Microsoft
ClipboardReads and changes what you copy, which matters for copied crypto addresses and passwordsMITRE; Microsoft
PasswordsMicrosoft lists passwords among the data Remcos collectsMicrosoft
Files and commandsSearch, upload, download, archive and delete files; run commands through the Windows command shell and scriptsMITRE
Your connectionSOCKS5 proxying through the infected PCMITRE

What this can cost you

Visiting the ficus.in website or seeing its name costs nothing by itself. The risks below apply to a Windows PC where a script fetched one of these pictures and Remcos then ran.

  • High

    Passwords and accounts

    A keylogger records what you type into every site, including new passwords you set on the same PC. Change passwords from another device, or the person watching sees the new ones too.

  • High

    Someone using your PC live

    Remcos is built for remote control. The controller can come back at any time, watch the screen and run commands while you are signed in.

  • High

    Money and crypto

    Clipboard access means a copied wallet address can be swapped, and a bank session opened on the PC can be watched. Crypto sent to the wrong address cannot be recalled.

  • Medium

    Camera, microphone and private files

    MITRE and Microsoft list webcam pictures, audio recording and file download. Documents and photos on the PC are exposed.

  • Medium

    More malware on the same PC

    Seqrite found the same picture campaign delivering several families, and in some cases Remcos itself installed AgentTesla, a password stealer.

  • Low

    Nothing, if you only saw the name or visited the site

    A name in a block list, a log or a warning is not an infection, and the reported files are offline now.

What you may notice, and what you may not

Remcos is designed to stay hidden. The signs below come from the sources and from what they imply; none is certain, and many victims notice nothing.

SignWhat the reports show
A Run key entry you did not makeMITRE says Remcos adds itself to HKCU\Software\Microsoft\Windows\CurrentVersion\Run
A registry key or mutex named RemcosMicrosoft's sample created HKEY_CURRENT_USER\SOFTWARE\Remcos-YTPKR1; Seqrite's samples used the mutex Rmc-IB3RDF. Names change between builds, so their absence proves nothing
caspol.exe or msbuild.exe running with no reasonSeqrite describes Remcos injected into these genuine Windows programs. Most home users never run them
A Defender detection naming RemcosMicrosoft detects the family as Backdoor:Win32/Remcos; other Remcos names exist for other builds
Webcam light on, or a changed wallpaperMITRE lists webcam capture and wallpaper changes. This is our reading of the features, not a reported symptom
Accounts you did not touchLogins from new places, password reset emails and messages sent from your accounts follow from stolen passwords
Nothing at allHidden windows and files are among the listed features

How to check the PC for ficus.in (Remcos RAT, stego PNG files)

How a person ends up asking for these pictures

Nobody types a file address like hxxps://ficus[.]in/img/img_205551.png on purpose. The request comes from a program, so the real question is how that program got onto the PC. We cannot say for this site; the routes below are those the sources describe for Remcos and the picture trick.

  1. 1

    An email attachment

    Seqrite's campaign began with an Excel file posing as a genuine document, and MITRE lists spearphishing with Excel attachments for Remcos. Opening the file is what starts the chain.

  2. 2

    A file from an unknown source

    Microsoft's advice for Remcos is to avoid opening files that do not come from a legitimate source. Invoices, orders and shipping notices that you did not expect are the usual disguise.

  3. 3

    Not by browsing the site

    Visiting the ficus.in home page in a browser is a different request from a script fetching a file from its img folder. We found nothing that says the site's own pages pushed Remcos to visitors.

If you own or run ficus.in

An old domain listed for malware files in an image folder is a typical sign of a hacked site. If the site is yours, treat the server as broken into until you know how the files got there. This is our advice for a site owner, not a procedure from a vendor.

Look in the img folder and in its history for files named img_ followed by six digits and .png that you did not upload, and keep a copy for your host before deleting them.

Then change every password for hosting, FTP, the database and the site's admin accounts, remove admin users you do not know, update the site software and its plugins, and ask your hosting provider for access logs from 15 September 2026 onward. Once the folder is clean, request a new check from URLhaus so the listing reflects it.

Check your PC before you delete anything

Start with the question that matters: did something on this PC contact ficus.in's img folder, or did you open an unexpected Office attachment, script or installer around mid September to early October 2026? If you saw the name in a firewall or DNS log from your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable. A remote access trojan needs the connection to be used.

  2. 2

    Find which device asked for the address

    If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question, and only if it asked for a file in the img folder.

  3. 3

    Look at the Run key and Startup apps

    MITRE names the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Open Registry Editor and look there for names or paths you do not recognise, especially files in your user folder or in Temp. A simpler view is Settings > Apps > Startup. Write down what you find; do not delete yet.

  4. 4

    Look for genuine programs that should not be running

    Open Task Manager and look for caspol.exe or msbuild.exe, or any process using a lot of network for no reason. Seqrite names these two as hiding places. They are real Windows programs, so their presence is not proof and their absence does not clear the PC.

  5. 5

    Search the registry for Remcos

    In Registry Editor, open HKEY_CURRENT_USER\SOFTWARE and look for a key whose name starts with Remcos. Microsoft's sample created one. Many builds rename it, so not finding one proves nothing.

  6. 6

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for a detection naming Remcos, such as Backdoor:Win32/Remcos, or for anything blocked or quarantined at the time of the first contact. Microsoft says offline scan results also appear here.

  7. 7

    Check your accounts from another device

    Look at the sign in activity of your email, bank and exchange accounts, and at crypto balances. This is quicker than any file check.

  8. 8

    A scan helps, but it does not clear the PC

    Microsoft notes that even after Defender removes a threat, remnant files and system changes can remain, and says to run a full scan with updated definitions. Treat a clean result as one data point. We did not infect a PC, so the order of this plan is our judgement from Microsoft's pages, not a tested result.

How to remove ficus.in (Remcos RAT, stego PNG files)

How to remove ficus.in

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to ficus.in or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever ficus.in installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The tags and every source we read describe a Windows threat. We found nothing that says the pictures on ficus.in affect anything else.

Your deviceWhat we knowWhat to do
MacMITRE lists Remcos for Windows only, and the chain Seqrite describes uses Windows scripts and Windows programsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source we read describes Remcos on iOSNothing to remove. If you typed passwords on a page you do not trust, change them
AndroidNo source we read mentions itNothing to remove for this threat; change passwords if you entered any

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything you typed, copied or stored on it while the trojan was there. The order matters: another device first, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, run a Defender Offline scan, check the Run key and Startup, reset Windows if unsure
The order of actions if Remcos may have run on a PC. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Use your phone or another computer. Start with email, because it resets everything else, then bank, work, cloud storage and crypto exchanges. Anything typed on the PC while it was watched is already known.

  2. 2

    Sign out other sessions and turn on two step sign in

    Most email and bank accounts let you sign out of all devices and add a second step at sign in. Do both, and check that the recovery email and phone number are still yours.

  3. 3

    Move crypto first if a wallet was on the PC

    If a seed phrase or wallet file was ever on the PC, or you copied one, assume it is known. Create a new wallet on a clean device and move the funds there.

  4. 4

    Run Microsoft Defender Offline

    Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes outside the normal Windows. Results are under Protection history. If BitLocker is on, Microsoft says to suspend it first.

  5. 5

    Remove what the check found, with care

    If the Run key, Startup apps or the registry showed an entry you can tie to Remcos, delete it and the file it points to. If you cannot tell, do not guess: the safe answer is the reset below.

  6. 6

    If you are not sure, reset Windows

    In Windows 11 the reset sits at Settings > System > Recovery > Reset this PC. Microsoft says keeping personal files removes apps and settings, and removing everything also deletes your files. For a PC that may have been under remote control, the full wipe does not depend on finding every piece. Microsoft calls the reset the most disruptive option and says to back up first.

  7. 7

    Restore only documents by hand

    Copy back documents and photos, not programs, and not a full system image from after the first contact. Install apps from their makers' own sites.

  8. 8

    Watch your money and your accounts

    Check card statements and exchange logs for a few weeks, and turn on alerts. If your accounts were used to send messages, tell your contacts not to open the links.

Keep a PC out of this kind of chain

The picture is a late step. Every source we read starts earlier, with a file a person opened.

Do

  • Treat an unexpected Office attachment as an attack, even when it looks like an invoice or an order. Seqrite's campaign began with exactly that.
  • Keep Windows, Office and Microsoft Defender updated; Seqrite's chain abused an Office flaw from 2017.
  • Show file endings in File Explorer so a script posing as a document is visible.
  • Get programs from their makers' own sites or from the Microsoft Store.
  • Use a password manager and two step sign in, so one stolen password is not enough.
  • Keep a backup of documents on a disk that you unplug.

Don't

  • Do not open attachments from senders you do not expect.
  • Do not run cracked programs or downloads from sites that promise free versions of paid software.
  • Do not trust a file because it looks like a picture when a program, not you, is the one asking for it.
  • Do not change your passwords on the PC you suspect.
  • Do not rely on a quiet scan to say that you are safe.

Questions about ficus.in (Remcos RAT, stego PNG files)

What is ficus.in?

It is a web address registered in India since 2010 that URLhaus, the malware tracking project of abuse.ch, lists for ten picture files in its img folder, reported between 15 September and 1 October 2026.

All ten are tagged stego and nine are tagged RemcosRAT. The pattern looks like a site whose folder was misused, but we cannot confirm that. We did not download the files.

Is ficus.in safe to visit?

The ten reported files are marked offline, and our plain request on 8 October 2026 got only a redirect to the www address, which clears nothing. We cannot say whether the site is clean now.

Do not download or run files from it, and do not run anything that fetches files from its img folder. Visiting a page is not the same as the script requests in the reports.

What does stego mean on a PNG file?

It is short for steganography, hiding data inside another file. Seqrite describes pictures that hide base64 text between the markers <<BASE64 START>> and <<BASE64 END>>. The file still opens as an ordinary picture.

A script that is already running reads the hidden part, decodes it and starts it, so the picture is a carrier, not something that infects you by being viewed.

What is Remcos?

Remcos is software sold by Breaking Security as remote control and surveillance software and used by criminals as a remote access trojan.

MITRE lists keylogging, screenshots, webcam and microphone capture, clipboard theft, file transfer and remote commands. Microsoft adds password collection. It starts at sign in through the Run key and can hide inside genuine Windows programs.

I saw ficus.in in my firewall or DNS log. Am I infected?

Not necessarily, and the name alone proves nothing. If the log shows a request to a file in the img folder, a program on that device asked for it, and a person does not usually do that by hand. Find which device it was, disconnect it, and do the checks on this page:

  • Run key
  • Startup apps
  • Task Manager
  • Protection history
  • a Defender Offline scan

How do I remove Remcos from Windows?

Change your passwords from another device first. Then run a Microsoft Defender Offline scan from Windows Security, Virus and threat protection, Scan options, check the Run key and Startup apps for entries you did not make, and delete those you can tie to Remcos.

If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages and did not test this on an infected PC.

What can Remcos see and take?

According to MITRE and Microsoft:

  • every key you type
  • screenshots
  • webcam pictures
  • microphone recordings
  • the clipboard
  • passwords
  • files the controller searches for

It can also run commands and use your PC as a proxy. Treat every password, session login and wallet that was on the PC as known, and change them from another device.

I own ficus.in. What should I do?

Treat the server as broken into. Look for img_NNNNNN.png files you did not upload, keep copies for your host, then delete them.

Change all hosting, FTP, database and admin passwords, remove unknown admin users, update the site software and plugins, and ask your host for access logs from mid September 2026. Then ask URLhaus to recheck the listing.

Does ficus.in affect Mac, iPhone or Android?

We found nothing that says so. MITRE lists Remcos for Windows only, and the chain Seqrite describes uses Windows scripts and programs. On a Mac, iPhone or Android phone there is nothing to remove for this threat; if you typed a password on a page you do not trust, change it.

Will Fortect remove ficus.in?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For ficus.in, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: ficus.in (Remcos RAT, stego PNG files)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year