mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
7.2 KiB
7.2 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | ||||
|---|---|---|---|---|---|---|---|---|
| Remcos | 2021-09-23 | true |
|
Try in Splunk Security Cloud{: .btn .btn--success}
Description
Leverage searches that allow you to detect and investigate unusual activities that might relate to the Remcos RAT trojan, including looking for file writes associated with its payload, screencapture, registry modification, UAC bypassed, persistence and data collection..
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2021-09-23
- Author: Teoderick Contreras, Splunk
- ID: 2bd4aa08-b9a5-40cf-bfe5-7d43f13d496c
Narrative
Remcos or Remote Control and Surveillance, marketed as a legitimate software for remotely managing Windows systems is now widely used in multiple malicious campaigns both APT and commodity malware by threat actors.
Detections
Reference
- https://success.trendmicro.com/solution/1123281-remcos-malware-information
- https://attack.mitre.org/software/S0332/
- [https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos#:
:text=Remcos%20(acronym%20of%20Remote%20Control,used%20to%20remotely%20control%20computers.&text=Remcos%20can%20be%20used%20for,been%20used%20in%20hacking%20campaigns.](https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos#::text=Remcos%20(acronym%20of%20Remote%20Control,used%20to%20remotely%20control%20computers.&text=Remcos%20can%20be%20used%20for,been%20used%20in%20hacking%20campaigns.)
source | version: 1