Remcos RAT
Commodity remote-access trojan (RAT) sold as malware-as-a-service by Breaking-Security.Net since ~2016. Windows-native, C++ with MSVCP60 STL, standard IAT, no packer. Distributed in versioned "Pro" builds with builder-generated encrypted RCData configuration.
Build Stack
- MSVC C++ with MSVCP60.dll C++ standard library (observed Jul 2016 and Jan 2017 builds)
- PE32 GUI or console, 4 sections (.text .rdata .data .rsrc)
- No packer, no obfuscation, no anti-debug beyond sandbox string checks
- Unsigned (all observed samples)
- RCData resource
SETTINGSholds encrypted config blob (245–803 bytes observed) - Heavy std::basic_string and iostream usage; builder likely emits C++ source compiled with legacy toolchain
Deploy / TTPs
- T1547.001 — Registry Run / Explorer Policies\Run persistence
- T1547.004 — Winlogon Userinit hijack
- T1548.002 — eventvwr-uac-bypass (eventvwr.exe auto-elevate via mscfile handler)
- T1056.001 / T1056.002 — Keylogger + clipboard capture (SetWindowsHookExA)
- T1113 — Screenshot capture (GDIPlus / StretchBlt)
- T1123 — Microphone capture (WINMM waveIn*)
- T1125 — Webcam capture
- T1057 — Process enumeration (Toolhelp32 API)
- T1217 — Browser credential theft (Chrome, Firefox, IE storage)
- T1005 — File manager / upload / download
- T1071.001 — Raw TCP C2 with
[DataStart]frame delimiter and keep-alive heartbeat - T1105 — Payload update via URLDownloadToFileA / InternetOpenUrlA fallback
Capabilities
- credential-dumping-browser-storage
- keylogging-SetWindowsHookExA
- clipboard-hijack-clipboard-apis
- screenshot-capture-gdiplus
- webcam-capture-directshow
- microphone-capture-wavein
- file-manager-upload-download
- process-enumeration-toolhelp32
- registry-modification-run-keys
- uac-bypass-eventvwr-mscfile
- uac-disable-EnableLUA-registry
- raw-tcp-c2-DataStart-framing
- http-fallback-download
- sandbox-evasion-string-checks
- mutex-singleton-Remcos_Mutex_Inj
- process-hollowing-NtUnmapViewOfSection
Variants / Aliases
- Remcos ("Remote Control & Surveillance")
- RemcosRAT
- Breaking-Security.Net vendor label
Notable Analyses
3bd53455— v1.1 Free, Jul 2016, 303-byte SETTINGS RCData, filenameeastvillageeatery.exe(restaurant lure masquerade), earliest confirmed Remcos in corpus (nine months before v1.7 Pro). Identical MSVCP60 build fingerprint. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/3bd5345502072fdb537ae2f36daaf4c8b0c36058484bb52887a57fa59381795f.html]d9950b15— v1.7 Pro, Jan 2017, 480-byte SETTINGS RCData, no VS_VERSIONINFO resource, filenameBackdoor.exe(no masquerade), full process-hollowing IAT. Static-only (CAPE skipped). ^[/intel/analyses/d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867.html]4818d00f— v1.7 Pro, Jan 2017, 429-byte SETTINGS RCData (enlarged config), process hollowing engine, eventvwr UAC bypass + EnableLUA fallback, static-only (no CAPE).5a1e57f7b0— sibling with 531-byte SETTINGS RCData (enlarged config vs 245-byte sibling)0f723826— v1.7 Pro, Jan 2017, unencrypted IAT, SETTINGS RCData blob. Full static report available.6114904c— v1.7 Pro, Jan 2017, 616-byte SETTINGS RCData, no VS_VERSIONINFO resource, identical string profile to0f723826. ^[/intel/analyses/6114904c95e9d95dc436f3a7b9059499d3d045dad3f30000ba06f85d8ae57a87.html]c6193af6— v1.7 Pro, Jan 2017, 593-byte SETTINGS RCData (largest observed in corpus), identical build/imports to0f723826.39848daa— v1.7 Pro, Jan 2017, 803-byte SETTINGS RCData (largest in corpus, supersedes 593-byte sibling), identical build/imports/string profile to0f723826; Backdoor.exe filename. Static-only (CAPE skipped).65d3a51a— v1.7 Pro, Jan 2017, 406-byte SETTINGS RCData, no VS_VERSIONINFO, filenameBackdoor.exe(no masquerade), full process-hollowing IAT, eventvwr UAC bypass + EnableLUA fallback. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html]522ff9a1— v1.7 Pro, Jan 2017, 384-byte SETTINGS RCData, no VS_VERSIONINFO, filenameBackdoor.exe, standard build stack identical to0f723826. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c.html]a6ccd895— v1.7 Pro, Jul 2016, 303-byte SETTINGS RCData (mid-size between 245-byte baseline and 384-byte sibling), UPX-packed, filenameeastvillageeatery.exe(restaurant lure masquerade), identical MSVCP60 build fingerprint. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a.html]
Related
- eventvwr-uac-bypass — technique page for the mscfile hijack
- embedded-rcdata-config — concept page for encrypted RCData payload staging