Trojan.Remcos

Short bio

Trojan.Remcos is Malwarebytes’ detection name for a Remote Administration Tool (RAT) targeting Windows systems.

Type and source of infection

Trojan.Remcos typically infects a system by embedding a specially-crafted settings file into an Office document, this allows an attacker can trick a user to run malicious code without any further warning or notification. The code is XML code which allows for any binary with parameters to be executed. This code is used to download and execute the REMCOS RAT.

Aftermath

Trojan.Remcos gives the threat actor full control over the infected system and allows them to run keyloggers and surveillance (audio + screenshots) mode. This means:

  • Data/information about the system may have been stolen
  • User credentials may have been stolen
  • Digital coins may have been stolen
  • Affected system may be susceptible to further attacks and/or infection due to a backdoor that was opened

Protection

Malwarebytes protects users from Trojan.Remcos by using Application Behavior Protection.

Malwarebytes blocks Trojan.Remcos

Remediation

Malwarebytes can detect and remove Trojan.Remcos without further user interaction.

  1. Please download Malwarebytes to your desktop.
  2. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  3. Then click Finish.
  4. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  5. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  6. When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  7. Restart your computer when prompted to do so.

Traces/IOCs

Files:

.SettingContent.ms

PcHealths.exe

Hashes:

8710e87642371c828453d59c8cc4edfe8906a5e8fdfbf2191137bf1bf22ecf81

fc0fa7c20adf0eaf0538cec14e37d52398a08d91ec105f33ea53919e7c70bb5a

ff64d7dc2f60fd79304639393cf70fed82e3eb1395d9f331ba123bd4e5f75923

 

Cybersecurity info you can’t do without

Want to stay informed on the latest news in cybersecurity? Sign up for our newsletter and learn how to protect your computer from threats.

Select your language