Remcos is a long-established commercial Windows remote-access trojan, written in C++/ASM, with custom command-and-control infrastructure. Millenium RAT is a newer family that abuses the Telegram Bot API for C2 and moved from .NET (2.x) to native C++ (4.x).
Both are sold commercially, but their C2 architectures differ significantly. Remcos detection focuses on its custom C2 protocol and infrastructure; Millenium RAT detection focuses on anomalous Telegram Bot API traffic and AppData persistence. Both warrant behavioral correlation.
The comparison illustrates how the RAT landscape splits between custom-C2 families (Remcos, njRAT, AsyncRAT) and cloud-platform-abuse families (Millenium RAT, ToxicEye). The latter blends into legitimate traffic, making network detection more about process-context than infrastructure-blocklisting.
