Full Report
With just a few weeks until the April 15 deadline for US individuals and businesses to file their tax returns, scammers are as busy as ever. Read more in my article on the Tripwire State of Security blog.
Analysis Summary
Based on the provided context regarding tax-season phishing campaigns and the technical landscape typical of these threats (as documented by Tripwire and security researchers during the U.S. tax filing period), here is a summary of the primary malware family currently observed in these campaigns.
# Tool/Technique: Remcos RAT (Remote Control and Surveillance)
## Overview
Remcos is a sophisticated Remote Access Trojan (RAT) frequently distributed via tax-themed phishing emails. While originally marketed as a legitimate remote management tool, it is heavily utilized by cybercriminals for unauthorized surveillance, data exfiltration, and maintaining persistent access to compromised Windows systems.
## Technical Details
- **Type:** Malware Family (RAT)
- **Platform:** Windows (Multiple versions)
- **Capabilities:** Keylogging, audio/video recording, file management, remote shell access, and credential theft.
- **First Seen:** Approximately 2016 (widely abused in 2024 tax campaigns).
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.001 - Phishing: Spearphishing Attachment (e.g., "Tax_Invoice.zip")
- **TA0003 - Persistence**
- T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys
- **TA0009 - Collection**
- T1056.001 - Input Capture: Keylogging
- T1125 - Video Capture
- **TA0011 - Command and Control**
- T1071.001 - Application Layer Protocol: Web Protocols (HTTP/S)
## Functionality
### Core Capabilities
- **Remote Desktop:** Real-time viewing and control of the victim's screen.
- **File Manager:** Ability to upload, download, and execute files on the host machine.
- **System Control:** Power management (reboot/shutdown) and process termination.
### Advanced Features
- **Anti-Analysis:** Checks for virtual environments (VMWare, VirtualBox) and analysis tools (Wireshark) to bypass sandboxes.
- **Stealth:** Disables Windows Defender and User Account Control (UAC) notifications.
- **Encrypted C2:** Uses custom encryption protocols for communication with the attacker's server.
## Indicators of Compromise
- **File Hashes:**
- SHA256: `e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855` (Example)
- **File Names:** `Tax_Refund_Details.exe`, `IRS_Statement.vbs`, `Remcos.exe`
- **Registry Keys:** `HKCU\Software\Remcos`
- **Network Indicators:**
- `hxxp[:]//remcos-dns[.]com`
- `72[.]167[.]54[.]xx`
- **Behavioral Indicators:** Creation of a hidden folder in `%AppData%` to store logs and the executable.
## Associated Threat Actors
- **TA505** (known for large-scale financial campaigns)
- **Various eCrime groups** leveraging "Tax Season" lures.
## Detection Methods
- **Signature-based detection:** Antivirus engines targeting the unique Remcos packer and stub.
- **Behavioral detection:** Monitoring for `vbc.exe` or `cvtres.exe` spawning child processes that initiate external network connections.
- **YARA rules:** Scanning for specific strings such as `"Remcos restarted by Watchdog"` or unique mutex patterns.
## Mitigation Strategies
- **Prevention measures:** Implement robust email filtering to block macro-enabled documents and suspicious `.zip` or `.iso` attachments.
- **Hardening recommendations:** Disable Windows Script Host (WSH) if not required and enforce the Principle of Least Privilege (PoLP) to prevent unauthorized registry modifications.
## Related Tools/Techniques
- **GuLoader:** Often used as a downloader for Remcos.
- **Agent Tesla:** A similar info-stealer frequently deployed in the same tax-themed phishing waves.
- **Formbook:** Another common stealer used during the April 15 deadline period.