Skip to main content
Mallory
MalwareUsed by 2 actors

RemCom

RemCom is an open-source remote execution utility for Windows, commonly described as a remote shell or telnet replacement and an open-source replacement for PsExec. It allows execution of processes on remote Windows systems and is commonly used by attackers for lateral movement and remote service-based execution within compromised networks. The content references detections and telemetry associated with RemCom activity, including Windows service creation events such as RemComSvc and datasets covering Windows Security, Sysmon, and System logs. RemCom has been observed in post-exploitation activity by multiple threat actors. Microsoft reported that MERCURY, now tracked as Mango Sandstorm and assessed with high confidence to be affiliated with Iran’s MOIS, used remote services with RemCom to run encoded PowerShell commands on internal systems after exploiting Log4j 2 vulnerabilities in SysAid Server instances targeting organizations in Israel. APT39 has used RemCom alongside NSSM to execute processes and for lateral movement, particularly in intrusions targeting telecommunications and travel organizations and other entities aligned with Iranian national interests. CrowdStrike reported that FANCY BEAR/APT28 used RemCOM to deploy tools during the 2016 DNC intrusion. Palo Alto Networks reported Stately Taurus (also known as Mustang Panda, BRONZE PRESIDENT, TA416, RedDelta, and Earth Preta) used RemCom for remote execution of exfiltration tools on uncompromised hosts during a long-running cyberespionage campaign against a Southeast Asian government. ESET also reported that IsaacWiper targeted specific machines previously compromised with RemCom, which was described as being used by attackers for lateral movement within compromised networks. High-confidence indicators directly mentioned in the content include the service name RemComSvc and the existence of SHA-256 hashes for RemCom shared by Microsoft in related intrusion reporting, though the specific hash values are not provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
MuddyWater

Remote services (leveraging RemCom tool) to run encoded PowerShell commands within organizations.

via microsoft generalmicrosoft.com
APT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

via mitre attackattack.mitre.org
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

T1588.002ToolEvidence1

"obtained and leveraged publicly-available tools for intrusion activities."

Execution

1 technique
T1569.002Service ExecutionEvidence2
TacticExecution

The following analytic identifies the execution of RemCom.exe, an open-source alternative to PsExec, used for lateral movement and remote command execution.

Persistence

1 technique
T1543.003Windows ServiceEvidence1

Windows Service Create RemComSvc ... Windows Service

T1543.003Windows ServiceEvidence1

Windows Service Create RemComSvc ... Windows Service

T1003OS Credential DumpingEvidence1

Consistent with GRU techniques and 'methods of persistence' identified by computer forensic investigators in other intrusions, the hackers again used X-Agent to log keystrokes, take screenshots, and gather system data; used a lateral-movement tool called RemCom; and used Mimikatz, a credential-harvesting tool.

Lateral Movement

3 techniques
T1021.002SMB/Windows Admin SharesEvidence2

Example-script execution artifacts 7 psexec.py , smbexec.py , atexec.py , dcomexec.py , RemCom artifacts

T1021.004SSHEvidence1

Remote services (leveraging RemCom tool) to run encoded PowerShell commands within organizations.

T1570Lateral Tool TransferEvidence1

Description Atomic Testing of Remcom MITRE ATT&CK Techniques ... The following datasets were collected during this attack simulation: ... /datasets/attack_techniques/T1570/remcom/

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

RemCom | Mallory