Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Two
ID: 8e19299b-2b00-5851-9177-873f945fafab
STIX ID: report--8e19299b-2b00-5851-9177-873f945fafab
Feed Name: Elastic Security Labs
Threat Score
This technical write-up (part two of a series) analyzes REMCOS RAT execution and post-compromise capabilities: it describes the watchdog persistence/injection logic, offline keylogger modes and file handling, screenshot and screen-specific capture features, audio recording behavior, file storage/encryption flags, and the C2 communication protocol including packet structure and example packet-building code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
