Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1055 Process Injection |
ToolRemcos | Remcos has a command to hide itself by injecting into another process. |
| T1056.001 Keylogging |
ToolRemcos | Remcos has a command for keylogging. |
| T1059.003 Windows Command Shell |
ToolRemcos | Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1123 Audio Capture |
ToolRemcos | Remcos can capture data from the system’s microphone. |
| T1125 Video Capture |
ToolRemcos | Remcos can access a system’s webcam and take pictures. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolRemcos | Remcos can add itself to the Registry key |
| T1548.002 Bypass User Account Control |
ToolRemcos | Remcos has a command for UAC bypassing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.