New Remcos Campaign

New Remcos Campaign Distributed Through Fake Shipping Document www.fortinet.com/blog/thre…

FortiGuard Labs discovered a new phishing campaign in the wild. The campaign delivers a new variant of Remcos, a commercial lightweight remote access tool (RAT) with a wide range of capabilities, including system resource management, remote surveillance, network management, and Remcos agent management.

I conducted an in-depth investigation into this malicious campaign. This analysis covers how the phishing email initializes the attack, how the attached Word document downloads an RTF file, the vulnerability the attack leverages within the RTF file, the VBScript and PowerShell code, how a fileless .NET module is loaded and executed in a PowerShell process, and how the fileless Remcos agent is downloaded and loaded using process hollowing.

The analysis also details this Remcos variant’s internal configuration block, packet structures, and capabilities across six categories, which are illustrated with examples.

Edward Kiledjian @ekiledjian