Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
ToolRemcos | Remcos can list all windows on victim systems. |
| T1012 Query Registry |
ToolRemcos | Remcos can obtain Registry data from targeted systems. |
| T1027.013 Encrypted/Encoded File |
ToolRemcos | Remcos can use string encryption to hinder analysis. |
| T1033 System Owner/User Discovery |
ToolRemcos | Remcos can enumerate the username on targeted hosts. |
| T1057 Process Discovery |
ToolRemcos | Remcos can discover running processes on compromised machines. |
| T1059.003 Windows Command Shell |
ToolRemcos | Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1059.005 Visual Basic |
ToolRemcos | Remcos can execute VBS remotely. |
| T1059.007 JavaScript |
ToolRemcos | Remcos has the ability to execute JavaScript remotely. |
| T1070 Indicator Removal |
ToolRemcos | Remcos can clean saved cookies and logins from the web browser. |
| T1070.004 File Deletion |
ToolRemcos | Remcos can delete files and folders from victim machines. |
| T1082 System Information Discovery |
ToolRemcos | Remcos can collect the OS version and process architecture of compromised hosts. |
| T1083 File and Directory Discovery |
ToolRemcos | Remcos can search for files on the infected machine. |
| T1090 Proxy |
ToolRemcos | Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying. |
| T1105 Ingress Tool Transfer |
ToolRemcos | Remcos can upload and download files to and from the victim’s machine. |
| T1112 Modify Registry |
ToolRemcos | Remcos has full control of the Registry, including the ability to modify it. |
| T1113 Screen Capture |
ToolRemcos | Remcos takes automated screenshots of the infected machine. |
| T1115 Clipboard Data |
ToolRemcos | Remcos steals and modifies data from the clipboard. |
| T1123 Audio Capture |
ToolRemcos | Remcos can capture data from the system’s microphone. |
| T1204.002 Malicious File |
ToolRemcos | Remcos has been executed by luring victims into opening malicious email attachments including Excel files. |
| T1491.001 Internal Defacement |
ToolRemcos | Remcos has the ability to modify the desktop wallpaper. |
| T1529 System Shutdown/Reboot |
ToolRemcos | Remcos can shutdown and restart remote devices. |
| T1543.003 Windows Service |
ToolRemcos | Remcos can terminate, suspend, and resume a process by PID. |
| T1560.001 Archive via Utility |
ToolRemcos | Remcos can zip files and folders for upload. |
| T1564 Hide Artifacts |
ToolRemcos | Remcos can modify file attributes to hide the file. |
| T1566.001 Spearphishing Attachment |
ToolRemcos | Remcos has been spread through emails containing malicious documents. |
| T1573.002 Asymmetric Cryptography |
ToolRemcos | Remcos can use TLS to encrypt C2 communication. |
| T1614 System Location Discovery |
ToolRemcos | Remcos can identify the location of targeted devices. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.