1200KM / tool
Remcos — Attack Tool
Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Remcos
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Gamaredon Group · G0047 · Pinned relationship source (relationship--7c7b3761-80ff-4469-ad5b-9cc9a26078db)
- Gorgon Group · G0078 · Pinned relationship source (relationship--bfe45239-7fa4-45a5-bb47-86c4ae46906c)
- APT-C-36 · G0099 · Pinned relationship source (relationship--afabeca2-f30b-40c6-a2d5-aee4be37aa29)
- LazyScripter · G0140 · Pinned relationship source (relationship--22d01d2c-6c2e-4e59-98ac-393aef16ffe3)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1010 · Application Window Discovery · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1115 · Clipboard Data · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1204.002 · Malicious File · Detection rules & anomalies
- T1491.001 · Internal Defacement · Detection rules & anomalies
- T1497.001 · System Checks · Detection rules & anomalies
- T1529 · System Shutdown/Reboot · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1568 · Dynamic Resolution · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1614 · System Location Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Firewall Rule Modification · DC0051
- Firmware Modification · DC0004
- Host Status · DC0018
- Instance Enumeration · DC0075
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Modification · DC0010
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.