ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!
General

Remy's RAT - x64 C2 Loader & Remote Shell (Windows 10/11)

Submitted by Remio at 20-04-2025, 05:31 PM


Remy's RAT - x64 C2 Loader & Remote Shell (Windows 10/11)
429 Views
#2
Remy's RAT - x64 C2 Loader & Remote Shell (Windows 10/11)

- 60KB standalone (MSVC, no dependencies, single filer)
- nice and simple anti-debug, anti-VM, anti-sandbox checks
- Persistence; Registry, Scheduled Tasks, Services
- auto proxy detection
- Jittered reconnect loop

Limitations on Win10/11:
1. fodhelper.exe UAC bypass - as of recent is usually patched, use new one simply;
3. Basic sandbox checks - may fail against advanced setups
4. Static C2 - could trigger network alerts
5. Process creation - may trigger AMSI

Suggested improvements for live use:
- change fodhelper for newer UAC bypass
- Add DGA for C2 rotation or some shit
- use process/DLL injection or some side loading techniques
- upgrade XOR to AES/RC4
- Add API obfuscation;
1
Reply


Messages In This Thread
RE: Remy's RAT - x64 C2 Loader & Remote Shell (Windows 10/11) - by Remio - 20-04-2025, 05:33 PM


Users browsing this thread: