ATT&CKReferencesSecurelist Remexi Jan 2019

Securelist Remexi Jan 2019

Legezo, D. (2019, January 30). Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities. Retrieved April 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareRemexi

Remexi has a command to capture active windows on the machine and retrieve window titles.

T1027.013
Encrypted/Encoded File
MalwareRemexi

Remexi obfuscates its configuration data with XOR.

T1041
Exfiltration Over C2 Channel
MalwareRemexi

Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel.

T1047
Windows Management Instrumentation
MalwareRemexi

Remexi executes received commands with wmic.exe (for WMI commands).

T1053.005
Scheduled Task
MalwareRemexi

Remexi utilizes scheduled tasks as a persistence mechanism.

T1056.001
Keylogging
MalwareRemexi

Remexi gathers and exfiltrates keystrokes from the machine.

T1059.003
Windows Command Shell
MalwareRemexi

Remexi silently executes received commands with cmd.exe.

T1059.005
Visual Basic
MalwareRemexi

Remexi uses AutoIt and VBS scripts throughout its execution process.

T1071.001
Web Protocols
MalwareRemexi

Remexi uses BITSAdmin to communicate with the C2 server over HTTP.

T1083
File and Directory Discovery
MalwareRemexi

Remexi searches for files on the system.

T1113
Screen Capture
MalwareRemexi

Remexi takes screenshots of windows of interest.

T1115
Clipboard Data
MalwareRemexi

Remexi collects text from the clipboard.

T1140
Deobfuscate/Decode Files or Information
MalwareRemexi

Remexi decrypts the configuration data using XOR with 25-character keys.

T1547.001
Registry Run Keys / Startup Folder
MalwareRemexi

Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism.

T1547.004
Winlogon Helper DLL
MalwareRemexi

Remexi achieves persistence using Userinit by adding the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit.

T1560
Archive Collected Data
MalwareRemexi

Remexi encrypts and adds all gathered browser data into files for upload to C2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.