As promised, here we are with the second part of the Malware Report dedicated to GuLoader distributing Remcos.
Remcos (Remote Control & Surveillance Software) is a software advertised by the company BreakingSecurity as a legitimate means of remote access.
According to various online publications, it also emerged that this software was developed by a German company, however, their headquarters are located in Rome, as can easily be seen on the company's official website.
It has also been proven, both by technical publications of renowned vendors and by the continuous CERT reports (Computer Emergency Response Team) Italian, which Remcos is and has been used in several hacking campaigns because it can act as a backdoor on the system, granting full access to a remote user.
Our report examines its functionality, focusing in particular on how it can perform privilege elevation on the system, bypassing the Windows user access control.
If you wish to learn more, here is the link to our full report.
In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/