Remsec

S0125

Malware.View on attack.mitre.org

About this malware

Remsec is a modular backdoor that has been used by Strider and appears to have been designed primarily for espionage purposes. Many of its modules are written in Lua.

Techniques used30

Procedure examples30

TechniqueProcedure example
T1003.002
Security Account Manager

Remsec can dump the SAM database.

T1016
System Network Configuration Discovery

Remsec can obtain information about network configuration, including the routing table, ARP cache, and DNS cache.

T1018
Remote System Discovery

Remsec can ping or traceroute a remote host.

T1025
Data from Removable Media

Remsec has a package that collects documents from any inserted USB sticks.

T1027.013
Encrypted/Encoded File

Some data in Remsec is encrypted using RC5 in CBC mode, AES-CBC with a hardcoded key, RC4, or Salsa20. Some data is also base64-encoded.

T1033
System Owner/User Discovery

Remsec can obtain information about the current user.

T1036.005
Match Legitimate Resource Name or Location

The Remsec loader implements itself with the name Security Support Provider, a legitimate Windows function. Various Remsec .exe files mimic legitimate file names used by Microsoft, Symantec, Kaspersky, Hewlett-Packard, and VMWare. Remsec also disguised malicious modules using similar filenames as custom network encryption software on victims.

T1046
Network Service Discovery

Remsec has a plugin that can perform ARP scanning as well as port scanning.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

Remsec can exfiltrate data via a DNS tunnel or email, separately from its C2 channel.

T1049
System Network Connections Discovery

Remsec can obtain a list of active connections and open ports.

T1052.001
Exfiltration over USB

Remsec contains a module to move data from airgapped networks to Internet-connected systems by using a removable USB device.

T1053.005
Scheduled Task

Remsec schedules the execution one of its modules by creating a new scheduler task.

T1055.001
Dynamic-link Library Injection

Remsec can perform DLL injection.

T1056.001
Keylogging

Remsec contains a keylogger component.

T1057
Process Discovery

Remsec can obtain a process list from the victim.

View all 30 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Strider Blog Open source
    Symantec Security Response. (2016, August 7). Strider: Cyberespionage group turns eye of Sauron on targets. Retrieved August 17, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.