ATT&CKReferencesRiskiq Remcos Jan 2018

Riskiq Remcos Jan 2018

Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1059.006
Python
ToolRemcos

Remcos uses Python scripts.

T1083
File and Directory Discovery
ToolRemcos

Remcos can search for files on the infected machine.

T1090
Proxy
ToolRemcos

Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.

T1105
Ingress Tool Transfer
ToolRemcos

Remcos can upload and download files to and from the victim’s machine.

T1112
Modify Registry
ToolRemcos

Remcos has full control of the Registry, including the ability to modify it.

T1113
Screen Capture
ToolRemcos

Remcos takes automated screenshots of the infected machine.

T1115
Clipboard Data
ToolRemcos

Remcos steals and modifies data from the clipboard.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.