Remote Control System (RCS), also known as Da Vinci and Crisis, was Hacking Team’s commercial government surveillance platform. It used a staged implant architecture—commonly Scout followed by Soldier or Elite—to compromise and remotely monitor target systems. RCS supported Windows, macOS, Linux, Android, and iOS targets, among other historical mobile platforms. Its capabilities included collection and exfiltration of files, browser data and passwords, clipboard contents, communications, keystrokes, screenshots, location data, and Wi-Fi credentials; interception or recording of email, instant messaging, Skype/VoIP calls, microphone and webcam feeds; and endpoint control designed to access data in plaintext at the device. Windows variants implemented persistence, process injection and API hooking, encrypted local staging of collected information, anti-virus and anti-analysis evasion, and self-removal functions. RCS was deployed through targeted social engineering, malicious files and links, executable lures masquerading as documents, and exploit-laden Office documents, including exploitation of known Microsoft Office vulnerabilities. Hacking Team sold RCS to government, law-enforcement, and intelligence customers. Documented targeting included journalists, activists, dissidents, opposition groups, and civil-society organizations in countries including Morocco, the UAE, Ethiopia, Mexico, and Uzbekistan. Research also identified RCS infrastructure and suspected government operators in numerous other countries. Post-2015 samples retained Hacking Team’s architecture and development patterns and were assessed with high confidence to have been developed by Hacking Team rather than merely derived from its leaked source code.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hacking Team enables clients to perform remote monitoring functions against citizens via their RCS (remote control systems), including their Da Vinci and Galileo platforms.
The attachment exploited CVE-2010-3333, an RTF parsing vulnerability in Microsoft Office. The document did not contain any bait content, and part of the malformed RTF that triggered the exploit was displayed in the document. | The first attacks we observed in the UAE involved a government-grade “lawful interception” trojan known as Remote Control System (RCS), sold by the Italian company Hacking Team.
Like the second file, the document also exploited the CVE-2012-0158 bug... The document exploited a bug in Microsoft Windows (CVE-2012-0158) to run a program that downloaded and executed a file... An update to Windows available since April 2012 fixes this bug. | In each case the spyware appeared to be RCS (Remote Control System), programmed and sold exclusively to governments by Milan-based Hacking Team.
Remote Control System (RCS) is sophisticated computer spyware marketed and sold exclusively to governments by Milan-based Hacking Team.
Remote Control System (RCS) is sophisticated computer spyware marketed and sold exclusively to governments by Milan-based Hacking Team.
Remote Control System (RCS) is sophisticated computer spyware marketed and sold exclusively to governments by Milan-based Hacking Team.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Hacking Team's flagship product, the Remote Control System (RCS), was detected in the wild at the beginning of 2018 in 14 different countries.
Hacking Team enables clients to perform remote monitoring functions against citizens via their RCS (remote control systems), including their Da Vinci and Galileo platforms.
The most controversial item found on Mexico's purchase order is a surveillance software known as “Remote Control System," which some Mexicans suspect the government used to spy on its own citizens or to conduct politically motivated hacks.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
The page, found at http://freeme.eu5.org/scandale%20(2).doc prompted the user for the installation of malicious java, file, 'adobe.jar'. This file then facilitated the installation of a multi-platform (OSX and Windows) backdoor.
A mysterious source had made three attempts to send malicious files to employees, claiming that they were news articles
when a fake document was used to implant malware on the computers of journalists who were critical of Morocco’s government
Here we see inline hooking of 'NtQuerySystemInformation' performed by the malware, a technique frequently used to allow process hiding... strings relating to popular anti-rootkit and anti-virus software, suggesting evasion of specific products
We also identify several cases where US-based spyware servers were disguised as the websites of US companies, including a small New York-based financial services firm related to an SEC investigation, a small Oregon newspaper, and ABC News. We believe that the disguises were designed to mislead targets if they discovered that their systems were communicating with these servers.
Processes such as iexexplorer.exe and wscntfy.exe are infected... This then infects the following processes: explorer.exe iexplore.exe wscntfy.exe reader_sl.exe VMwareUser.exe
RCS can record Skype calls, copy passwords, e-mails, files and instant messages...
“It is straightforward to grab the wallet.dat and related files and for malcode to get the password for this file when the user accesses their bitcoins”
RCS can record Skype calls, copy passwords, e-mails, files and instant messages, and turn on a computer or phone’s webcam and microphone to spy on nearby activity.
Citizen Lab reported that the command and control (C&C) server that the spyware sent his personal information back to was a website called ar-24[.]com...
In 2012 and early 2013, most Hacking Team servers, when viewed in a web browser, were disguised as http://www.google.com, i.e., they loaded a page that immediately redirected to Google. This redirection is never invoked by the spyware itself, and seems designed to make a Hacking Team RCS server appear to be another website to an individual who loads the server address into their web browser.
The report showed that computers infected with RCS send surveillance data back to the government operator through a series of servers in multiple third countries, called a proxy chain or circuit. This is to prevent someone who discovers a copy of the spyware or an infected computer from tracing it back to the government.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial spyware used to target journalists from the Mamfakinch citizen-media group in Morocco.
Spyware that provides real-time access to computers and smartphones.
Commercial spyware/backdoor sold by Hacking Team for infecting and monitoring computers and smartphones, including encrypted communications, with persistence, process injection, API hooking, anti-security evasion, and multi-stage delivery.
Government-grade spyware suite sold by Hacking Team for covert surveillance. It can exfiltrate files, record Skype calls, emails, instant messages, and passwords, and activate webcams and microphones. It uses proxy-chain collection infrastructure to obscure the operator and has been delivered via phishing and exploit documents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.