ATT&CKReferencesFortinet Remcos Feb 2017

Fortinet Remcos Feb 2017

Bacurio, F., Salvio, J. (2017, February 14). REMCOS: A New RAT In The Wild. Retrieved November 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1055
Process Injection
ToolRemcos

Remcos has a command to hide itself by injecting into another process.

T1056.001
Keylogging
ToolRemcos

Remcos has a command for keylogging.

T1059.003
Windows Command Shell
ToolRemcos

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1123
Audio Capture
ToolRemcos

Remcos can capture data from the system’s microphone.

T1125
Video Capture
ToolRemcos

Remcos can access a system’s webcam and take pictures.

T1547.001
Registry Run Keys / Startup Folder
ToolRemcos

Remcos can add itself to the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1548.002
Bypass User Account Control
ToolRemcos

Remcos has a command for UAC bypassing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.