RCS, also known as Remote Control System and widely associated with the HackingTeam surveillance platform, is a commercial spyware suite designed for covert monitoring and remote compromise of endpoint and mobile devices. Public reporting has referred to the malware and related platform under multiple names including Galileo, Da Vinci, Korablin, Morcut, and Crisis. The platform has included desktop agents for Windows, macOS, and Linux, and mobile targeting capabilities for Android, jailbroken iOS devices, and BlackBerry devices.
RCS is built for post-compromise surveillance and data collection. Reported capabilities include covert installation of platform-specific agents, persistence on infected systems, remote command execution, and exfiltration of victim data to operator-controlled infrastructure. On Apple platforms, documented samples used anti-analysis and defense-evasion techniques, including custom packing, protected Mach-O segments, and anti-debugging measures. The malware family has also been observed using infected desktop systems as a bridge to deploy spyware onto connected mobile devices.
Delivery has varied by platform and operator. Reported infection vectors include malicious links and trojanized applications, including Android applications bundled with RCS spyware and delivery from compromised PCs or Macs to connected mobile devices. The platform has been sold to government customers and has been repeatedly linked to lawful-intercept and intelligence-style surveillance operations, including use against activists and other persons of interest. A post-2015 macOS sample indicated continued maintenance of the codebase after HackingTeam’s breach, with newer OS X compatibility logic alongside longstanding tradecraft.
RCS is notable as one of the best-known commercial intrusion spyware platforms of the 2010s, combining cross-platform surveillance functionality with modular deployment and operator-oriented tooling for covert collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The RCS (Remote Control System) malware (aka Galileo, Da Vinci, Korablin, Morcut and Crisis) includes multiple components, including desktop agents for Windows, macOS and perhaps unsurprisingly… Linux.
Like the second file, the document also exploited the CVE-2012-0158 bug... The document exploited a bug in Microsoft Windows (CVE-2012-0158) to run a program that downloaded and executed a file... An update to Windows available since April 2012 fixes this bug.
The attachment exploited CVE-2010-3333, an RTF parsing vulnerability in Microsoft Office. The document did not contain any bait content, and part of the malformed RTF that triggered the exploit was displayed in the document.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The HackingTeam’s RCS delivered its Spyware from infected PCs and Macs to jailbroken iOS devices and BlackBerry phones
The RCS (Remote Control System) malware (aka Galileo, Da Vinci, Korablin, Morcut and Crisis) includes multiple components, including desktop agents for Windows, macOS and perhaps unsurprisingly… Linux.
The RCS (Remote Control System) malware (aka Galileo, Da Vinci, Korablin, Morcut and Crisis) includes multiple components, including desktop agents for Windows, macOS and perhaps unsurprisingly… Linux.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
when a fake document was used to implant malware on the computers of journalists who were critical of Morocco’s government
the chief technical author wrote in Italian, referring to the Ethiopian clients. “found the source of the attack because these geniuses used the same email address they had used in the previous attack to send the doc with the exploit”
In 2014, a Hacking Team customer, later revealed to be the Saudi Ministry of Interior’s General Investigation Directorate (GID), circulated links to an Android Application (APK) file containing a copy of the Qatif Today news application bundled with Hacking Team’s RCS spyware.
The configuration file as usual is encrypted... First we locate the configuration file encryption key and then decrypt it.
Loading this into a disassembler and we get only a tiny amount of code, the rest is what appears to be junk code. This is pretty much a tell tale that this binary is packed. This points straight way to HackingTeam’s own packer, keypress, that can be found in the leaked source code.
We also identify several cases where US-based spyware servers were disguised as the websites of US companies, including a small New York-based financial services firm related to an SEC investigation, a small Oregon newspaper, and ABC News. We believe that the disguises were designed to mislead targets if they discovered that their systems were communicating with these servers.
What happens here is that the maximum VM protection is not executable and this is the reason why GDB is unable to access the memory. The fix is as simple as fixing the maximum protection to RWX (modify hex value to 8). That’s quite a nice anti-debugging trick I don’t remember every seeing before.
What happens here is that the maximum VM protection is not executable and this is the reason why GDB is unable to access the memory. The fix is as simple as fixing the maximum protection to RWX (modify hex value to 8). That’s quite a nice anti-debugging trick I don’t remember every seeing before.
RCS can record Skype calls, copy passwords, e-mails, files and instant messages...
The leaked tools included ... sophisticated platforms capable of providing remote access, keylogging, general information recording and exfiltration.
In 2012 and early 2013, most Hacking Team servers, when viewed in a web browser, were disguised as http://www.google.com, i.e., they loaded a page that immediately redirected to Google. This redirection is never invoked by the spyware itself, and seems designed to make a Hacking Team RCS server appear to be another website to an individual who loads the server address into their web browser.
The report showed that computers infected with RCS send surveillance data back to the government operator through a series of servers in multiple third countries, called a proxy chain or circuit. This is to prevent someone who discovers a copy of the spyware or an infected computer from tracing it back to the government.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spyware from Hacking Team used in malicious Android APKs and booby-trapped documents to infect targets for surveillance.
Commercial surveillance malware platform with remote access, keylogging, information recording, exfiltration, and Skype audio/video capture capabilities; includes Linux desktop agents.
Named spyware/tool mentioned in attribution analysis as part of broader comparison/background.
Spyware mentioned as a prior example of malware delivered from infected computers to mobile devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.