| Technique | Procedure example |
|---|---|
| T1010 Application Window Discovery |
Remcos can list all windows on victim systems. |
| T1012 Query Registry |
Remcos can obtain Registry data from targeted systems. |
| T1027 Obfuscated Files or Information |
Remcos uses RC4 and base64 to obfuscate data, including Registry entries and file paths. Remcos can also employ control flow flattening to hinder analysis. |
| T1027.013 Encrypted/Encoded File |
Remcos can use string encryption to hinder analysis. |
| T1033 System Owner/User Discovery |
Remcos can enumerate the username on targeted hosts. |
| T1055 Process Injection |
Remcos has a command to hide itself by injecting into another process. |
| T1056.001 Keylogging |
Remcos has a command for keylogging. |
| T1057 Process Discovery |
Remcos can discover running processes on compromised machines. |
| T1059.003 Windows Command Shell |
Remcos can launch a remote command line to execute commands on the victim’s machine. |
| T1059.005 Visual Basic |
Remcos can execute VBS remotely. |
| T1059.006 Python |
Remcos uses Python scripts. |
| T1059.007 JavaScript |
Remcos has the ability to execute JavaScript remotely. |
| T1070 Indicator Removal |
Remcos can clean saved cookies and logins from the web browser. |
| T1070.004 File Deletion |
Remcos can delete files and folders from victim machines. |
| T1082 System Information Discovery |
Remcos can collect the OS version and process architecture of compromised hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.