Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part One
ID: d2cc3659-b6d7-5965-a22c-caa0c07e8ea1
STIX ID: report--d2cc3659-b6d7-5965-a22c-caa0c07e8ea1
Feed Name: Elastic Security Labs
Threat Score
This report is a technical analysis of REMCOS v4.9.3 Pro, detailing how the malware loads and decrypts its embedded configuration, performs UAC bypass and optional UAC disabling, installs and persists on a host (with optional folder/binary hiding), injects into target processes via ZwMapViewOfSection/SetThreadContext/ResumeThread, and optionally cleans browser cookies/login files; it highlights configuration flags, logging modes, and detection notes useful for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
