RemoteCMD
MITRE ATT&CK: S0166 View on attack.mitre.org
Aliases: RemoteCMD
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:35:28
Targeted industries: government-and-public-sector defense-and-aerospace financial-services
Targeted regions: country_code:us country_code:cn
Context
RemoteCMD is a custom tool used by APT3 to execute commands on a remote system similar to SysInternal's PSEXEC functionality.
Detection coverage
- 140 Sigma rules
Malware & tools used
- Service Execution (attack-pattern)
- Scheduled Task (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- APT3 (threat-actor)
Reports & references
- web.archive.org — Buckeye Cyberespionage Group Shifts Gaze Us Hong Kong (report)
- MITRE ATT&CK — S0166 (report)