Remexi

S0375

Malware.View on attack.mitre.org

About this malware

Remexi is a Windows-based Trojan that was developed in the C programming language.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1010
Application Window Discovery

Remexi has a command to capture active windows on the machine and retrieve window titles.

T1027.013
Encrypted/Encoded File

Remexi obfuscates its configuration data with XOR.

T1041
Exfiltration Over C2 Channel

Remexi performs exfiltration over BITSAdmin, which is also used for the C2 channel.

T1047
Windows Management Instrumentation

Remexi executes received commands with wmic.exe (for WMI commands).

T1053.005
Scheduled Task

Remexi utilizes scheduled tasks as a persistence mechanism.

T1056.001
Keylogging

Remexi gathers and exfiltrates keystrokes from the machine.

T1059.003
Windows Command Shell

Remexi silently executes received commands with cmd.exe.

T1059.005
Visual Basic

Remexi uses AutoIt and VBS scripts throughout its execution process.

T1071.001
Web Protocols

Remexi uses BITSAdmin to communicate with the C2 server over HTTP.

T1083
File and Directory Discovery

Remexi searches for files on the system.

T1113
Screen Capture

Remexi takes screenshots of windows of interest.

T1115
Clipboard Data

Remexi collects text from the clipboard.

T1140
Deobfuscate/Decode Files or Information

Remexi decrypts the configuration data using XOR with 25-character keys.

T1547.001
Registry Run Keys / Startup Folder

Remexi utilizes Run Registry keys in the HKLM hive as a persistence mechanism.

T1547.004
Winlogon Helper DLL

Remexi achieves persistence using Userinit by adding the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit.

View all 16 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Securelist Remexi Jan 2019 Open source
    Legezo, D. (2019, January 30). Chafer used Remexi malware to spy on Iran-based foreign diplomatic entities. Retrieved April 17, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.