Remcos

S0332

Tool.View on attack.mitre.org

About this tool

Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.

Techniques used38

Procedure examples38

TechniqueProcedure example
T1010
Application Window Discovery

Remcos can list all windows on victim systems.

T1012
Query Registry

Remcos can obtain Registry data from targeted systems.

T1027
Obfuscated Files or Information

Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis.

T1027.013
Encrypted/Encoded File

Remcos can use string encryption to hinder analysis.

T1033
System Owner/User Discovery

Remcos can enumerate the username on targeted hosts.

T1055
Process Injection

Remcos has a command to hide itself by injecting into another process.

T1056.001
Keylogging

Remcos has a command for keylogging.

T1057
Process Discovery

Remcos can discover running processes on compromised machines.

T1059.003
Windows Command Shell

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1059.005
Visual Basic

Remcos can execute VBS remotely.

T1059.006
Python

Remcos uses Python scripts.

T1059.007
JavaScript

Remcos has the ability to execute JavaScript remotely.

T1070
Indicator Removal

Remcos can clean saved cookies and logins from the web browser.

T1070.004
File Deletion

Remcos can delete files and folders from victim machines.

T1082
System Information Discovery

Remcos can collect the OS version and process architecture of compromised hosts.

View all 38 procedure examples

Groups that use it4

Campaigns1

References2

  1. Riskiq Remcos Jan 2018 Open source
    Klijnsma, Y. (2018, January 23). Espionage Campaign Leverages Spear Phishing, RATs Against Turkish Defense Contractors. Retrieved November 6, 2018.
  2. Talos Remcos Aug 2018 Open source
    Brumaghin, E., Unterbrink, H. (2018, August 22). Picking Apart Remcos Botnet-In-A-Box. Retrieved November 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.