typeentityconfidencehighcreated2026-06-03updated2026-09-06malware-familyratc2persistencedefense-evasiondiscoveryexfiltration

Remcos RAT

Commodity remote-access trojan (RAT) sold as malware-as-a-service by Breaking-Security.Net since ~2016. Windows-native, C++ with MSVCP60 STL, standard IAT, no packer. Distributed in versioned "Pro" builds with builder-generated encrypted RCData configuration.

Build Stack

  • MSVC C++ with MSVCP60.dll C++ standard library (observed Jul 2016 and Jan 2017 builds)
  • PE32 GUI or console, 4 sections (.text .rdata .data .rsrc)
  • No packer, no obfuscation, no anti-debug beyond sandbox string checks
  • Unsigned (all observed samples)
  • RCData resource SETTINGS holds encrypted config blob (245–803 bytes observed)
  • Heavy std::basic_string and iostream usage; builder likely emits C++ source compiled with legacy toolchain

Deploy / TTPs

  • T1547.001 — Registry Run / Explorer Policies\Run persistence
  • T1547.004 — Winlogon Userinit hijack
  • T1548.002 — eventvwr-uac-bypass (eventvwr.exe auto-elevate via mscfile handler)
  • T1056.001 / T1056.002 — Keylogger + clipboard capture (SetWindowsHookExA)
  • T1113 — Screenshot capture (GDIPlus / StretchBlt)
  • T1123 — Microphone capture (WINMM waveIn*)
  • T1125 — Webcam capture
  • T1057 — Process enumeration (Toolhelp32 API)
  • T1217 — Browser credential theft (Chrome, Firefox, IE storage)
  • T1005 — File manager / upload / download
  • T1071.001 — Raw TCP C2 with [DataStart] frame delimiter and keep-alive heartbeat
  • T1105 — Payload update via URLDownloadToFileA / InternetOpenUrlA fallback

Capabilities

  • credential-dumping-browser-storage
  • keylogging-SetWindowsHookExA
  • clipboard-hijack-clipboard-apis
  • screenshot-capture-gdiplus
  • webcam-capture-directshow
  • microphone-capture-wavein
  • file-manager-upload-download
  • process-enumeration-toolhelp32
  • registry-modification-run-keys
  • uac-bypass-eventvwr-mscfile
  • uac-disable-EnableLUA-registry
  • raw-tcp-c2-DataStart-framing
  • http-fallback-download
  • sandbox-evasion-string-checks
  • mutex-singleton-Remcos_Mutex_Inj
  • process-hollowing-NtUnmapViewOfSection

Variants / Aliases

  • Remcos ("Remote Control & Surveillance")
  • RemcosRAT
  • Breaking-Security.Net vendor label

Notable Analyses

  • 3bd53455 — v1.1 Free, Jul 2016, 303-byte SETTINGS RCData, filename eastvillageeatery.exe (restaurant lure masquerade), earliest confirmed Remcos in corpus (nine months before v1.7 Pro). Identical MSVCP60 build fingerprint. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/3bd5345502072fdb537ae2f36daaf4c8b0c36058484bb52887a57fa59381795f.html]
  • d9950b15 — v1.7 Pro, Jan 2017, 480-byte SETTINGS RCData, no VS_VERSIONINFO resource, filename Backdoor.exe (no masquerade), full process-hollowing IAT. Static-only (CAPE skipped). ^[/intel/analyses/d9950b1564b0d38cbaec507c8e1cdc41df08d8a638e5f050ff71cb5ceed84867.html]
  • 4818d00f — v1.7 Pro, Jan 2017, 429-byte SETTINGS RCData (enlarged config), process hollowing engine, eventvwr UAC bypass + EnableLUA fallback, static-only (no CAPE).
  • 5a1e57f7b0 — sibling with 531-byte SETTINGS RCData (enlarged config vs 245-byte sibling)
  • 0f723826 — v1.7 Pro, Jan 2017, unencrypted IAT, SETTINGS RCData blob. Full static report available.
  • 6114904c — v1.7 Pro, Jan 2017, 616-byte SETTINGS RCData, no VS_VERSIONINFO resource, identical string profile to 0f723826. ^[/intel/analyses/6114904c95e9d95dc436f3a7b9059499d3d045dad3f30000ba06f85d8ae57a87.html]
  • c6193af6 — v1.7 Pro, Jan 2017, 593-byte SETTINGS RCData (largest observed in corpus), identical build/imports to 0f723826.
  • 39848daa — v1.7 Pro, Jan 2017, 803-byte SETTINGS RCData (largest in corpus, supersedes 593-byte sibling), identical build/imports/string profile to 0f723826; Backdoor.exe filename. Static-only (CAPE skipped).
  • 65d3a51a — v1.7 Pro, Jan 2017, 406-byte SETTINGS RCData, no VS_VERSIONINFO, filename Backdoor.exe (no masquerade), full process-hollowing IAT, eventvwr UAC bypass + EnableLUA fallback. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/65d3a51a436d55aff9c6845dfb8974ce4ee9456e4d3beb6dd2c8b3c4e9fdcd0d.html]
  • 522ff9a1 — v1.7 Pro, Jan 2017, 384-byte SETTINGS RCData, no VS_VERSIONINFO, filename Backdoor.exe, standard build stack identical to 0f723826. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/522ff9a14cba958db505cf1a0d850f9d92a6394c0383952d0914086fdbc58f3c.html]
  • a6ccd895 — v1.7 Pro, Jul 2016, 303-byte SETTINGS RCData (mid-size between 245-byte baseline and 384-byte sibling), UPX-packed, filename eastvillageeatery.exe (restaurant lure masquerade), identical MSVCP60 build fingerprint. Static-only (CAPE skipped — no Windows guest). ^[/intel/analyses/a6ccd89558c4b5cd2fec2512b846e14620be2cb3489f85b99203a9e4b9751d6a.html]

Related