RemoteCMD

MITRE ATT&CK: S0166 View on attack.mitre.org

Aliases: RemoteCMD

Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:35:28

Targeted industries: government-and-public-sector defense-and-aerospace financial-services

Targeted regions: country_code:us country_code:cn

Context

RemoteCMD is a custom tool used by APT3 to execute commands on a remote system similar to SysInternal's PSEXEC functionality.

Detection coverage

  • 140 Sigma rules

Malware & tools used

  • Service Execution (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

  • APT3 (threat-actor)

Reports & references

  • web.archive.org — Buckeye Cyberespionage Group Shifts Gaze Us Hong Kong (report)
  • MITRE ATT&CK — S0166 (report)

External references