ATT&CKReferencesFortinet Remcos Campaign NOV 2024

Fortinet Remcos Campaign NOV 2024

Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1010
Application Window Discovery
ToolRemcos

Remcos can list all windows on victim systems.

T1012
Query Registry
ToolRemcos

Remcos can obtain Registry data from targeted systems.

T1027.013
Encrypted/Encoded File
ToolRemcos

Remcos can use string encryption to hinder analysis.

T1033
System Owner/User Discovery
ToolRemcos

Remcos can enumerate the username on targeted hosts.

T1057
Process Discovery
ToolRemcos

Remcos can discover running processes on compromised machines.

T1059.003
Windows Command Shell
ToolRemcos

Remcos can launch a remote command line to execute commands on the victim’s machine.

T1059.005
Visual Basic
ToolRemcos

Remcos can execute VBS remotely.

T1059.007
JavaScript
ToolRemcos

Remcos has the ability to execute JavaScript remotely.

T1070
Indicator Removal
ToolRemcos

Remcos can clean saved cookies and logins from the web browser.

T1070.004
File Deletion
ToolRemcos

Remcos can delete files and folders from victim machines.

T1082
System Information Discovery
ToolRemcos

Remcos can collect the OS version and process architecture of compromised hosts.

T1083
File and Directory Discovery
ToolRemcos

Remcos can search for files on the infected machine.

T1090
Proxy
ToolRemcos

Remcos uses the infected hosts as SOCKS5 proxies to allow for tunneling and proxying.

T1105
Ingress Tool Transfer
ToolRemcos

Remcos can upload and download files to and from the victim’s machine.

T1112
Modify Registry
ToolRemcos

Remcos has full control of the Registry, including the ability to modify it.

T1113
Screen Capture
ToolRemcos

Remcos takes automated screenshots of the infected machine.

T1115
Clipboard Data
ToolRemcos

Remcos steals and modifies data from the clipboard.

T1123
Audio Capture
ToolRemcos

Remcos can capture data from the system’s microphone.

T1204.002
Malicious File
ToolRemcos

Remcos has been executed by luring victims into opening malicious email attachments including Excel files.

T1491.001
Internal Defacement
ToolRemcos

Remcos has the ability to modify the desktop wallpaper.

T1529
System Shutdown/Reboot
ToolRemcos

Remcos can shutdown and restart remote devices.

T1543.003
Windows Service
ToolRemcos

Remcos can terminate, suspend, and resume a process by PID.

T1560.001
Archive via Utility
ToolRemcos

Remcos can zip files and folders for upload.

T1564
Hide Artifacts
ToolRemcos

Remcos can modify file attributes to hide the file.

T1566.001
Spearphishing Attachment
ToolRemcos

Remcos has been spread through emails containing malicious documents.

T1573.002
Asymmetric Cryptography
ToolRemcos

Remcos can use TLS to encrypt C2 communication.

T1614
System Location Discovery
ToolRemcos

Remcos can identify the location of targeted devices.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.