Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three
ID: 3afb7104-03ff-5aca-9f9f-e7f25e37b50a
STIX ID: report--3afb7104-03ff-5aca-9f9f-e7f25e37b50a
Feed Name: Elastic Security Labs
This report analyzes the REMCOS RAT, documenting ~80% of its configuration fields (paths, persistence, logging, recording options, TLS configs) and ~95% of its C2 command set (remote execution, keylogger, screenshot/audio/webcam capture, credential and browser data theft, update/uninstall, UAC bypass). It includes integer-to-path mappings used by the malware, descriptions of how modules are loaded (DLLs/Nirsoft binaries), examples of extractor usage to modify config and trigger connections, and generated Visual Basic scripts used for uninstall/restart operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
