ficus.in: picture files hiding the Remcos remote access trojan, and what to do if a script fetched them
ficus.in is a web address, registered since 2010, that URLhaus lists ten times between 15 September and 1 October 2026 for picture files (img_*.png in its img folder) tagged stego, nine of them tagged RemcosRAT, a remote access trojan for Windows. A picture like that does not infect you when you look at it; it is a later stage that a script already running on a PC fetches.
If you only visited the site or saw the name in a log, nothing is proven. If something on your PC may have fetched these files, treat the PC as watched: change your passwords from another device, then scan and clean or reset Windows.
Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
If a script, loader or program that downloads picture files from ficus.in keeps coming back after uninstalling, a scan can find what reinstalls it.
Do it yourself · free Remove ficus.in (Remcos RAT, stego PNG files) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Ficus.in (Remcos RAT, stego PNG files): summary
| Type | A web folder that served PNG files tagged stego; nine of ten also tagged RemcosRAT and rat (a remote access trojan for Windows) |
|---|---|
| Risk | High if a script on your PC fetched its files: keystrokes, passwords, screen, camera, microphone and files may be taken. Low if you only saw the name or visited the site |
| Symptoms | Often none. A Run key entry you did not make, caspol.exe or msbuild.exe running with no reason, or a Defender detection naming Remcos |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove the startup entries, and reset Windows if you are not sure |
| Our check (8 October 2026) | One plain request: a redirect to https://www.ficus.in/, served by nginx. It clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 18 April 2010; first picture file reported 15 September 2026, last 1 October 2026; all ten offline on 8 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No detection name is known for the files on this site, because we did not open them. Microsoft detects the family as Backdoor:Win32/Remcos |
| Name | Ficus.in |
| Domain registered | 18 April 2010 |
| Evidence | 10 write-ups by security sites; details still limited |
| First seen | 15 September 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 8 October 2026 |
Facts checked on 8 October 2026 against the URLhaus data for ficus.in held in our database, RDAP, one plain request from our server (no browser), and published pages by MITRE ATT&CK, Microsoft and Seqrite Labs. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What ficus.in is, and what we know about it
ficus.in is not a program on your PC. It is a web address, registered in India since 2010, that the abuse.ch project URLhaus lists ten times between 15 September and 1 October 2026 for picture files in a folder called img. Nine are tagged RemcosRAT, a remote access trojan for Windows, and all ten are tagged stego. We found no public write-up of this address, so this page rests on URLhaus, our own plain request and what Microsoft, MITRE and Seqrite publish.
An old domain with a normal web address that suddenly serves malware pictures from an image folder usually means one of two things: the site was broken into and a stranger uses its folder as free storage, or the domain changed hands.
We cannot tell which from the outside. Either way, the files were there, and either way the advice for a visitor and for a PC owner is the same.
- 1
What URLhaus lists
Ten file addresses under hxxps://ficus[.]in/img/, each named img_ followed by six digits and the ending .png. The first was added on 15 September 2026, then one on 23 September, one on 24 September, five on 30 September and two on 1 October. All carry the threat label malware_download and the reporter abuse_ch. All ten were marked offline in our copy of the data on 8 October 2026.
- 2
What the tags mean
stego is short for steganography: data hidden inside another file, here a picture. RemcosRAT names Remcos, a remote control tool sold by a company called Breaking Security that criminals use as a trojan. rat means remote access trojan. Nine files carry all three tags; img_011624.png, added on 30 September, is tagged only stego.
- 3
What we could not confirm
We did not download any of the pictures, so we cannot tell you what is inside them, which Remcos build they carry or where it reports to. URLhaus shows tags, not a full analysis. We also do not know which program or email makes a victim's PC ask for these files. That first step is not visible from the server.
- 4
What this means for you
If you only visited the ficus.in website, or saw its name in a log or a warning, you are not infected by that alone. The risk is for a Windows PC where a script was already running and went to fetch one of these pictures. A person browsing the site has no reason to request a file named img_220032.png directly.
- Kind of threat
- A web folder that served PNG files tagged stego; nine of ten tagged RemcosRAT, a remote access trojan for Windows
- Where the files were
- hxxps://ficus[.]in/img/img_NNNNNN.png, on the normal secure web port
- Domain registered
- 18 April 2010, registrar Endurance International Group India Private Limited, status client transfer prohibited (RDAP, read 8 October 2026)
- URLhaus entries
- 10 file addresses, added 15 September to 1 October 2026; all 10 offline when we read the data on 8 October 2026
- Delivery trick
- Steganography: code hidden in picture files so the download looks like an image. The entry step on the victim's PC is not known
- Platform
- Windows. MITRE lists Remcos for Windows only. Nothing we read says these pictures affect Mac, iPhone or Android
What ficus.in (Remcos RAT, stego PNG files) does on an infected PC
What we checked on 8 October 2026, and what we could not
We sent one plain request to ficus.in from our server on 8 October 2026: no browser, no clicks, no file downloads. The server answered with a redirect (HTTP 301) to https://www.ficus.in/ and named its web server software as nginx/1.29.8. That is all a plain request shows, and it clears nothing.
Our check, 8 October 2026
- The domain answersHTTP 301, a permanent redirect to https://www.ficus.in/. The server header says nginx/1.29.8. This tells us the domain still has a working web server; it does not tell us what the site shows or whether it is clean.
- What a plain request cannot seeWe did not load the page in a browser, did not run its scripts and did not request the img folder. A hacked site can look normal on its front page while a folder deeper down holds malware.
- Notification requestOur tool found no mention of a browser notification request in the answer. With a redirect and no page body, there was little to see.
- URLhaus listingTen picture files in /img/ tagged stego; nine tagged RemcosRAT and rat; reported from 15 September to 1 October 2026.
- Files offline nowURLhaus marks all ten addresses offline. That means they no longer answered when checked. It does not mean the site was cleaned or that new file names cannot appear.
Treat its img folder as a malware source The rating comes from the ten URLhaus reports and their tags, not from our request. The site itself may belong to a real business whose server was misused. Do not run anything that downloads files from this address, and if you own the site, read the section for site owners below.
What happened to ficus.in, from registration to our check
The domain is sixteen years old, and the reports all fall within about two weeks. The dates come from RDAP and from the URLhaus data we hold; the times are UTC.
18 April 2010
The domain is registered
RDAP shows ficus.in registered on 18 April 2010 through Endurance International Group India Private Limited, with the status client transfer prohibited. A long history like this is typical of a real business site, not of a throwaway malware domain.
15 September 2026
The first picture is reported
At about 15:27 UTC abuse.ch adds img_214254.png, tagged RemcosRAT, rat and stego.
23 and 24 September 2026
Two more files
img_012405.png is added on 23 September at about 08:52 UTC and img_212442.png on 24 September at about 12:56 UTC, both with the same three tags.
30 September 2026
Five files in one day
img_220032.png at about 06:00 UTC, then img_221258.png, img_215413.png and img_220602.png between 12:38 and 12:42 UTC, all tagged RemcosRAT, rat and stego. img_011624.png follows at about 14:50 UTC, tagged only stego.

All ten URLhaus entries for ficus.in as we read them on 8 October 2026. The folder stays the same; the six digit file names change. 1 October 2026
The last two reports
img_210244.png and img_205551.png are added at about 16:12 UTC, both tagged RemcosRAT, rat and stego. This is the newest report we hold.
8 October 2026
All offline, and our check
All ten addresses are marked offline in the URLhaus data. Our plain request to the domain returns a redirect to the www address, served by nginx.
What the pattern suggests, and what it does not: new file names kept appearing in the same folder for more than two weeks, which looks like someone with ongoing write access to the folder rather than a single leftover file. That is our reading of the dates, not something any report says.
How a picture file can carry Remcos
A picture that hides code cannot hurt you by being opened or looked at. It works only when a script that is already running reads the hidden part and starts it. We did not see the files on ficus.in; this is how Seqrite describes a campaign whose main payload was Remcos.

- 1
A phishing attachment opens
Seqrite (17 March 2025) describes an Excel attachment that poses as a genuine file and abuses an old Office flaw, CVE-2017-0199, to request an .hta file from the internet. MITRE also lists spearphishing emails with Excel attachments as a way Remcos has spread.
- 2
Scripts fetch the next piece
In Seqrite's chain the .hta file holds VBScript that writes a batch file. The batch file downloads an obfuscated VBS script, and that script hides a base64 encoded PowerShell command. The PowerShell command is the part that downloads a picture.
- 3
The picture holds a program
Seqrite found picture files that hide base64 text between the markers <<BASE64 START>> and <<BASE64 END>>. The script searches the picture for those markers and decodes what lies between them into a loader. The picture still looks like an image to a filter that checks only file types.
- 4
The loader hides Remcos in a trusted program
Seqrite describes process hollowing: the loader starts caspol.exe or msbuild.exe from C:\Windows\SysWOW64, empties it and writes the malware into it. MITRE lists process injection for Remcos. In Task Manager the process then has a genuine Windows name.
- 5
Remcos connects to its controller
From then on a person elsewhere can use the PC. MITRE says Remcos encrypts its traffic with TLS and has used dynamic DNS addresses, so the connection does not stand out by its content.
Whether the pictures on ficus.in used the same markers, the same scripts or a different method is not known to us. The tags say only that something was hidden in them and that the hidden part was identified as Remcos.
What Remcos is
Remcos is sold openly as remote control and surveillance software by a company called Breaking Security, and criminals use it as a remote access trojan. The sources agree on what it can do; they differ in the details of each campaign.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | Closed source software marketed as remote control and surveillance software by Breaking Security, observed in malware campaigns | MITRE ATT&CK S0332 |
| Since when is it tracked? | MITRE created its entry on 29 January 2019; Microsoft published its Backdoor:Win32/Remcos entry on 3 August 2018 | MITRE; Microsoft |
| What does it do? | Keylogging, screenshots, webcam pictures, microphone recording, clipboard theft, file upload, download and deletion, remote commands | MITRE; Microsoft |
| How does it stay? | It adds itself to the Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, so it starts at sign in | MITRE |
| How does it hide? | A built in UAC bypass, process injection, hidden windows, hidden files, encrypted settings and checks for Sandboxie and VMware | MITRE |
| Who uses it? | MITRE names Gorgon Group, Gamaredon Group, LazyScripter and APT-C-36, and Operation Spalax | MITRE |
| What comes with it? | Seqrite found Remcos as the main payload of a picture campaign that also delivered AsyncRAT, DcRAT, AgentTesla and VIPKeyLogger | Seqrite |
| Which build is on ficus.in? | Not known. URLhaus gives only the tag RemcosRAT; we did not open the files | Not available |
What ficus.in (Remcos RAT, stego PNG files) can steal or download
What Remcos can take from a Windows PC
A remote access trojan gives a stranger a seat at your computer, so the list below is what such a person can do, not what every build does on its own. Each item is named by MITRE or Microsoft.
Reported as possible
- Every key you type
- Screenshots of your screen
- Webcam pictures
- Microphone recordings
- What you copy to the clipboard
- Passwords
- Files searched, uploaded and downloaded
- Files deleted
- Programs started or stopped
- Your PC used as a SOCKS5 proxy
- Saved browser cookies and logins wiped
| Data | Detail | Source |
|---|---|---|
| Keystrokes | Keylogging, started and stopped on command | MITRE; Microsoft |
| Screen | Automated screenshots | MITRE; Microsoft |
| Camera and microphone | Webcam pictures and audio recording | MITRE; Microsoft |
| Clipboard | Reads and changes what you copy, which matters for copied crypto addresses and passwords | MITRE; Microsoft |
| Passwords | Microsoft lists passwords among the data Remcos collects | Microsoft |
| Files and commands | Search, upload, download, archive and delete files; run commands through the Windows command shell and scripts | MITRE |
| Your connection | SOCKS5 proxying through the infected PC | MITRE |
What this can cost you
Visiting the ficus.in website or seeing its name costs nothing by itself. The risks below apply to a Windows PC where a script fetched one of these pictures and Remcos then ran.
- High
Passwords and accounts
A keylogger records what you type into every site, including new passwords you set on the same PC. Change passwords from another device, or the person watching sees the new ones too.
- High
Someone using your PC live
Remcos is built for remote control. The controller can come back at any time, watch the screen and run commands while you are signed in.
- High
Money and crypto
Clipboard access means a copied wallet address can be swapped, and a bank session opened on the PC can be watched. Crypto sent to the wrong address cannot be recalled.
- Medium
Camera, microphone and private files
MITRE and Microsoft list webcam pictures, audio recording and file download. Documents and photos on the PC are exposed.
- Medium
More malware on the same PC
Seqrite found the same picture campaign delivering several families, and in some cases Remcos itself installed AgentTesla, a password stealer.
- Low
Nothing, if you only saw the name or visited the site
A name in a block list, a log or a warning is not an infection, and the reported files are offline now.
What you may notice, and what you may not
Remcos is designed to stay hidden. The signs below come from the sources and from what they imply; none is certain, and many victims notice nothing.
| Sign | What the reports show |
|---|---|
| A Run key entry you did not make | MITRE says Remcos adds itself to HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
| A registry key or mutex named Remcos | Microsoft's sample created HKEY_CURRENT_USER\SOFTWARE\Remcos-YTPKR1; Seqrite's samples used the mutex Rmc-IB3RDF. Names change between builds, so their absence proves nothing |
| caspol.exe or msbuild.exe running with no reason | Seqrite describes Remcos injected into these genuine Windows programs. Most home users never run them |
| A Defender detection naming Remcos | Microsoft detects the family as Backdoor:Win32/Remcos; other Remcos names exist for other builds |
| Webcam light on, or a changed wallpaper | MITRE lists webcam capture and wallpaper changes. This is our reading of the features, not a reported symptom |
| Accounts you did not touch | Logins from new places, password reset emails and messages sent from your accounts follow from stolen passwords |
| Nothing at all | Hidden windows and files are among the listed features |
How to check the PC for ficus.in (Remcos RAT, stego PNG files)
How a person ends up asking for these pictures
Nobody types a file address like hxxps://ficus[.]in/img/img_205551.png on purpose. The request comes from a program, so the real question is how that program got onto the PC. We cannot say for this site; the routes below are those the sources describe for Remcos and the picture trick.
- 1
An email attachment
Seqrite's campaign began with an Excel file posing as a genuine document, and MITRE lists spearphishing with Excel attachments for Remcos. Opening the file is what starts the chain.
- 2
A file from an unknown source
Microsoft's advice for Remcos is to avoid opening files that do not come from a legitimate source. Invoices, orders and shipping notices that you did not expect are the usual disguise.
- 3
Not by browsing the site
Visiting the ficus.in home page in a browser is a different request from a script fetching a file from its img folder. We found nothing that says the site's own pages pushed Remcos to visitors.
If you own or run ficus.in
An old domain listed for malware files in an image folder is a typical sign of a hacked site. If the site is yours, treat the server as broken into until you know how the files got there. This is our advice for a site owner, not a procedure from a vendor.
Look in the img folder and in its history for files named img_ followed by six digits and .png that you did not upload, and keep a copy for your host before deleting them.
Then change every password for hosting, FTP, the database and the site's admin accounts, remove admin users you do not know, update the site software and its plugins, and ask your hosting provider for access logs from 15 September 2026 onward. Once the folder is clean, request a new check from URLhaus so the listing reflects it.
Check your PC before you delete anything
Start with the question that matters: did something on this PC contact ficus.in's img folder, or did you open an unexpected Office attachment, script or installer around mid September to early October 2026? If you saw the name in a firewall or DNS log from your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable. A remote access trojan needs the connection to be used.
- 2
Find which device asked for the address
If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question, and only if it asked for a file in the img folder.
- 3
Look at the Run key and Startup apps
MITRE names the key HKCU\Software\Microsoft\Windows\CurrentVersion\Run. Open Registry Editor and look there for names or paths you do not recognise, especially files in your user folder or in Temp. A simpler view is Settings > Apps > Startup. Write down what you find; do not delete yet.
- 4
Look for genuine programs that should not be running
Open Task Manager and look for caspol.exe or msbuild.exe, or any process using a lot of network for no reason. Seqrite names these two as hiding places. They are real Windows programs, so their presence is not proof and their absence does not clear the PC.
- 5
Search the registry for Remcos
In Registry Editor, open HKEY_CURRENT_USER\SOFTWARE and look for a key whose name starts with Remcos. Microsoft's sample created one. Many builds rename it, so not finding one proves nothing.
- 6
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for a detection naming Remcos, such as Backdoor:Win32/Remcos, or for anything blocked or quarantined at the time of the first contact. Microsoft says offline scan results also appear here.
- 7
Check your accounts from another device
Look at the sign in activity of your email, bank and exchange accounts, and at crypto balances. This is quicker than any file check.
- 8
A scan helps, but it does not clear the PC
Microsoft notes that even after Defender removes a threat, remnant files and system changes can remain, and says to run a full scan with updated definitions. Treat a clean result as one data point. We did not infect a PC, so the order of this plan is our judgement from Microsoft's pages, not a tested result.
How to remove ficus.in (Remcos RAT, stego PNG files)
How to remove ficus.in
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to ficus.in or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever ficus.in installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The tags and every source we read describe a Windows threat. We found nothing that says the pictures on ficus.in affect anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | MITRE lists Remcos for Windows only, and the chain Seqrite describes uses Windows scripts and Windows programs | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source we read describes Remcos on iOS | Nothing to remove. If you typed passwords on a page you do not trust, change them |
| Android | No source we read mentions it | Nothing to remove for this threat; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything you typed, copied or stored on it while the trojan was there. The order matters: another device first, then the PC.

- 1
Change passwords from a clean device
Use your phone or another computer. Start with email, because it resets everything else, then bank, work, cloud storage and crypto exchanges. Anything typed on the PC while it was watched is already known.
- 2
Sign out other sessions and turn on two step sign in
Most email and bank accounts let you sign out of all devices and add a second step at sign in. Do both, and check that the recovery email and phone number are still yours.
- 3
Move crypto first if a wallet was on the PC
If a seed phrase or wallet file was ever on the PC, or you copied one, assume it is known. Create a new wallet on a clean device and move the funds there.
- 4
Run Microsoft Defender Offline
Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes outside the normal Windows. Results are under Protection history. If BitLocker is on, Microsoft says to suspend it first.
- 5
Remove what the check found, with care
If the Run key, Startup apps or the registry showed an entry you can tie to Remcos, delete it and the file it points to. If you cannot tell, do not guess: the safe answer is the reset below.
- 6
If you are not sure, reset Windows
In Windows 11 the reset sits at Settings > System > Recovery > Reset this PC. Microsoft says keeping personal files removes apps and settings, and removing everything also deletes your files. For a PC that may have been under remote control, the full wipe does not depend on finding every piece. Microsoft calls the reset the most disruptive option and says to back up first.
- 7
Restore only documents by hand
Copy back documents and photos, not programs, and not a full system image from after the first contact. Install apps from their makers' own sites.
- 8
Watch your money and your accounts
Check card statements and exchange logs for a few weeks, and turn on alerts. If your accounts were used to send messages, tell your contacts not to open the links.
Keep a PC out of this kind of chain
The picture is a late step. Every source we read starts earlier, with a file a person opened.
Do
- Treat an unexpected Office attachment as an attack, even when it looks like an invoice or an order. Seqrite's campaign began with exactly that.
- Keep Windows, Office and Microsoft Defender updated; Seqrite's chain abused an Office flaw from 2017.
- Show file endings in File Explorer so a script posing as a document is visible.
- Get programs from their makers' own sites or from the Microsoft Store.
- Use a password manager and two step sign in, so one stolen password is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not open attachments from senders you do not expect.
- Do not run cracked programs or downloads from sites that promise free versions of paid software.
- Do not trust a file because it looks like a picture when a program, not you, is the one asking for it.
- Do not change your passwords on the PC you suspect.
- Do not rely on a quiet scan to say that you are safe.
Questions about ficus.in (Remcos RAT, stego PNG files)
What is ficus.in?
It is a web address registered in India since 2010 that URLhaus, the malware tracking project of abuse.ch, lists for ten picture files in its img folder, reported between 15 September and 1 October 2026.
All ten are tagged stego and nine are tagged RemcosRAT. The pattern looks like a site whose folder was misused, but we cannot confirm that. We did not download the files.
Is ficus.in safe to visit?
The ten reported files are marked offline, and our plain request on 8 October 2026 got only a redirect to the www address, which clears nothing. We cannot say whether the site is clean now.
Do not download or run files from it, and do not run anything that fetches files from its img folder. Visiting a page is not the same as the script requests in the reports.
What does stego mean on a PNG file?
It is short for steganography, hiding data inside another file. Seqrite describes pictures that hide base64 text between the markers <<BASE64 START>> and <<BASE64 END>>. The file still opens as an ordinary picture.
A script that is already running reads the hidden part, decodes it and starts it, so the picture is a carrier, not something that infects you by being viewed.
What is Remcos?
Remcos is software sold by Breaking Security as remote control and surveillance software and used by criminals as a remote access trojan.
MITRE lists keylogging, screenshots, webcam and microphone capture, clipboard theft, file transfer and remote commands. Microsoft adds password collection. It starts at sign in through the Run key and can hide inside genuine Windows programs.
I saw ficus.in in my firewall or DNS log. Am I infected?
Not necessarily, and the name alone proves nothing. If the log shows a request to a file in the img folder, a program on that device asked for it, and a person does not usually do that by hand. Find which device it was, disconnect it, and do the checks on this page:
- Run key
- Startup apps
- Task Manager
- Protection history
- a Defender Offline scan
How do I remove Remcos from Windows?
Change your passwords from another device first. Then run a Microsoft Defender Offline scan from Windows Security, Virus and threat protection, Scan options, check the Run key and Startup apps for entries you did not make, and delete those you can tie to Remcos.
If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages and did not test this on an infected PC.
What can Remcos see and take?
According to MITRE and Microsoft:
- every key you type
- screenshots
- webcam pictures
- microphone recordings
- the clipboard
- passwords
- files the controller searches for
It can also run commands and use your PC as a proxy. Treat every password, session login and wallet that was on the PC as known, and change them from another device.
I own ficus.in. What should I do?
Treat the server as broken into. Look for img_NNNNNN.png files you did not upload, keep copies for your host, then delete them.
Change all hosting, FTP, database and admin passwords, remove unknown admin users, update the site software and plugins, and ask your host for access logs from mid September 2026. Then ask URLhaus to recheck the listing.
Does ficus.in affect Mac, iPhone or Android?
We found nothing that says so. MITRE lists Remcos for Windows only, and the chain Seqrite describes uses Windows scripts and programs. On a Mac, iPhone or Android phone there is nothing to remove for this threat; if you typed a password on a page you do not trust, change it.
Will Fortect remove ficus.in?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For ficus.in, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- MITRE ATT&CK: Remcos, S0332 (modified 23 April 2026) (read October 8, 2026)
- Microsoft Security Intelligence: Backdoor:Win32/Remcos (updated 25 September 2023) (read October 8, 2026)
- Seqrite Labs: New Steganographic Campaign Distributing Multiple Malware (17 March 2025) (read October 8, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 8, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 8, 2026)