Threat Advisory

Remcos RAT New TTPS – Detection & Response

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Remcos is a remote access trojan – a malware used to take remote control over infected PCs. It was initially noticed in 2016 and has since evolved. It is widely accessible on the dark web and is updated once a month with new features. This trojan is created and sold to clients by a “business” called Breaking Security. Although Breaking Security promises that the program is only available to those who intend to use it for legal purposes, in reality Remcos RAT gives clients all the necessary features to launch potentially destructive attacks. The malware can be purchased with different cryptocurrencies. It can also capture screenshots, record keystrokes on infected machines, and send the collected information to host servers. Remcos trojan can be delivered in different forms. Based on RAT’s analysis, it can be spread as an executable file with the name that should convince users to open it, or it pretends to be a Microsoft Word file to download and execute the main payload. Remcos completes the invasion by employing obfuscation and anti-debugging tactics, prevalent malware delivery methods. Remcos RAT is a piece of malware that targets Windows-based computers and provides the attacker complete control over the machine[/subscribe_to_unlock_form]

Summary:

Remcos is a remote access trojan – a malware used to take remote control over infected PCs. It was initially noticed in 2016 and has since evolved. It is widely accessible on the dark web and is updated once a month with new features. This trojan is created and sold to clients by a “business” called Breaking Security. Although Breaking Security promises that the program is only available to those who intend to use it for legal purposes, in reality Remcos RAT gives clients all the necessary features to launch potentially destructive attacks. The malware can be purchased with different cryptocurrencies. It can also capture screenshots, record keystrokes on infected machines, and send the collected information to host servers. Remcos trojan can be delivered in different forms. Based on RAT’s analysis, it can be spread as an executable file with the name that should convince users to open it, or it pretends to be a Microsoft Word file to download and execute the main payload. Remcos completes the invasion by employing obfuscation and anti-debugging tactics, prevalent malware delivery methods. Remcos RAT is a piece of malware that targets Windows-based computers and provides the attacker complete control over the machine[emaillocker id="1283"]

References:

The following reports contain further technical details:

https://www.socinvestigation.com/remcos-rat-new-ttps-detection-response/

[/emaillocker]
crossmenu