Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a February 15, 2017 report, SecurityWeek said Fortinet researchers had observed Remcos in live attacks. Their analysis described a Remcos v1.7.3 Pro sample delivered through malicious Office documents and capable of remote surveillance, credential theft, and command execution. The report is a snapshot of that sample and period—not evidence of Remcos activity or detection coverage today.

What Remcos RAT was in the 2017 report

Remcos is described in the report as a remote access tool (RAT), software that lets an operator control or monitor a computer remotely. SecurityWeek’s Ionut Arghire reported that Remcos had appeared on hacking forums in 2016 and that Fortinet researchers had encountered it in live attacks by February 2017. The analyzed server component was based on Remcos v1.7.3 Pro, which the developer’s website reportedly said was released on January 23, 2017.

The report quoted Fortinet researchers: “More and more applications like Remcos are being released publicly, luring new perpetrators with their easy usage.” That observation concerned the availability and usability of tools at the time; it does not establish current Remcos prevalence.

How the reported attacks delivered and ran Remcos

The analyzed malicious Office documents were named Quotation.xls or Quotation.doc and were reportedly delivered by email. Their obfuscated macros called shell commands. Fortinet described use of Event Viewer (eventvwr.exe) in a User Account Control (UAC) bypass technique.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The report also says the Remcos server component had its own UAC-bypass function and describes a routine that reverted a modified registry setting after elevation. These are observations about the 2017 sample, not a signature that applies to every Remcos version or current attack.

What the analyzed Remcos sample could do

The client interface reportedly included Connections, Automatic Tasks, Local Settings, Builder, Event Log, and About tabs. The Connections tab showed active connections and system information, and offered the operator actions including:

  • Taking screenshots and searching files.
  • Viewing processes and executing commands.
  • Logging keystrokes and stealing passwords.
  • Accessing a webcam and microphone.
  • Downloading and executing code.

Automatic Tasks

Fortinet highlighted an Automatic Tasks feature that could be configured to run functions automatically after a connection, without a manual command from the client. Researchers characterized this as enabling an “infiltrate-exfiltrate-exit” sequence. The report does not say how often attackers used this feature; its presence in the client is not proof that it was used in every attack.

Settings and packing reported for the sample

The Local Settings tab allowed configuration of ports and passwords. The report says the same password was used for authentication and as a key for RC4 traffic encryption. It also says the analyzed sample used UPX and MPRESS1 packing, with an additional custom packer layered over MPRESS1. These details describe the sample examined in 2017, not necessarily later versions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the report does—and does not—establish

SecurityWeek reported a license price range of $58 to $389 at the time, varying by license period and number of “masters” or clients. This is a historical figure, not a current price. The report provides no infection count, victim count, prevalence statistic, or detection-rate measurement.

It therefore cannot answer how common Remcos is now, what current campaigns may be doing, what capabilities later versions have, or which present-day security products detect it. Those questions require newer threat reporting and current, product-specific evidence.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Source

SecurityWeek, Ionut Arghire, “Easy-to-Use Remcos RAT Spotted in Live Attacks,” February 15, 2017.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.