CNCMachineRMS is a Windows remote access trojan and second-stage loader used to provide durable post-compromise access. It has been observed at the end of a BabaDeda loader chain initiated through ClickFix social-engineering lures, including fake fix or fake CAPTCHA prompts that trick users into launching a malicious execution chain. The intrusion abuses a legitimately signed IBM SPSS WinWrap Basic IDE executable for DLL sideloading, then uses multiple decoy DLLs and shellcode execution through a legitimate Windows API to load the final implant while blending into normal application behavior.
The malware is built for remote administration rather than commodity credential theft. Reported capabilities include an interactive shell, file management, screenshot capture, host profiling, multiple persistence mechanisms, local account backdoor creation, and staged retrieval and execution of additional payloads. It supports numerous typed loader commands for launching MSI packages, executables, DLLs, scripts, batch files, and archive-based payloads, making it suitable for follow-on operator activity and broader hands-on-keyboard intrusion operations.
CNCMachineRMS collects system and environment information such as host identity, domain context, SID, privilege level, operating system and hardware details, firmware serials, installed security products, network adapter information, open ports, installed applications, and running processes. It stores configuration, local state, and command tasking in a custom serialized container format and uses runtime API resolution and stack-built strings to reduce static visibility. Local state is padded with random data to frustrate simple hash- or size-based detection.
Persistence has been observed through autorun mechanisms including Run-key and scheduled-task abuse, with masquerading designed to resemble legitimate IBM SPSS WinWrap Basic IDE activity. The malware can also create local accounts and add them to privileged groups, extending attacker access beyond the implant itself. Some builds contain virtualization-detection logic, although at least one analyzed campaign disabled those checks through configuration.
For command and control, CNCMachineRMS uses a custom binary protocol over TCP port 443 that is distinct from TLS despite using that port. It can resolve command-and-control infrastructure through DNS over HTTPS, reducing visibility in local DNS telemetry. The malware has been associated with ClickFix-driven delivery chains and should be treated as an access platform indicative of likely follow-on post-exploitation activity on compromised Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence is re-asserted on a loop every 150 seconds for the registry and every 875 seconds for the scheduled task... The same string is used as the scheduled task name.
Rodel notes that CNCMachineRMS includes several features typical of RATs, including: Interactive shell
22120 PS_SCRIPT Loader powershell -NoProfile -ExecutionPolicy Bypass -File
It passes the shellcode through EnumTimeFormatsEx, a harmless Windows date-formatting interface, so Windows itself calls the code.
Persistence is re-asserted on a loop every 150 seconds for the registry and every 875 seconds for the scheduled task... The same string is used as the scheduled task name.
Windows event IDs 4720 and 4732, the local account backdoor creating users and adding them to privileged groups.
Persistence is re-asserted on a loop every 150 seconds for the registry and every 875 seconds for the scheduled task... The same string is used as the scheduled task name.
There are no cleartext APIs or strings anywhere in the shellcode. APIs are resolved at runtime from hashes, and strings are built on the stack by a custom cipher.
In this case, WinWrapIDE.exe is clean and legitimately signed. The attackers exploit its ability to activate a scripting engine through COM, directing it to a dropped DLL.
The native engine behind vmdetector_scan_light is far more thorough... covering GPU and OpenGL renderer checks, DXGI adapter enumeration, CPUID hypervisor vendor strings, PCI and device IDs, driver and service and process names, and SMBIOS registry paths.
Before any of that, the decoy library fingerprints the environment: computer name, username, system and Windows and temp and current directory paths, tick count, system and local time... alongside sandbox and analysis evasion checks.
Extended recon. Monitors, drives, battery, network adapters, domain controller details, open TCP and UDP ports with owning PID
The browser related strings that are present resolve to default browser detection and a running process list... Extended recon... process list.
Identity. Computer name, username, domain, SID, elevation status... Platform. OS, build, edition, version, architecture... Hardware. CPU vendor and clock, core count, RAM total and usage, GPU and VRAM...
What it does ship with is an access toolkit: an interactive shell, a file manager...
The native engine behind vmdetector_scan_light is far more thorough... covering GPU and OpenGL renderer checks, DXGI adapter enumeration, CPUID hypervisor vendor strings, PCI and device IDs, driver and service and process names, and SMBIOS registry paths.
The RAT communicated with 89.110.110.119 over TCP port 443. Although the traffic used port 443, it was not protected by TLS and did not resemble any previously known C2 protocol. | This post describes the binary command-and-control (C2) protocol used by CNCMachineRMS, a recently identified remote access trojan (RAT).
The payload resolves its C2 domain over DNS over HTTPS, using dns.google, cloudflare-dns.com and dns.quad9.net.
One notable behavior is the malware’s use of DNS over HTTPS (DoH). Rather than sending the C2 domain lookup to the system’s usual DNS resolver, CNCMachineRMS sends the query over HTTPS to an external DoH provider.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A recently identified remote access trojan that uses a binary C2 protocol over TCP port 443 without TLS for its main C2 traffic, and uses DNS over HTTPS (DoH) to resolve its C2 domains via external providers such as dns.google, cloudflare-dns.com, and dns.quad9.net.
A recently identified remote access trojan that uses a custom binary C2 protocol over TCP port 443 without TLS for its main C2 traffic, resolves its C2 domains via DNS over HTTPS providers, and includes RAT capabilities such as an interactive shell, file manager, and screen capture.
A previously undocumented remote access trojan used in ClickFix campaigns. It provides lasting control of Windows systems, including an interactive command shell, file browsing/management, screenshots, creation of new local accounts, persistence, host reconnaissance, beaconing, and the ability to retrieve and execute additional payloads via a custom scripting language.
A previously undocumented remote access trojan delivered via a ClickFix chain that abuses signed IBM SPSS WinWrap Basic IDE. It provides lasting remote control of Windows systems, including an interactive shell, file browsing/manager, screenshots, creation of new local accounts, persistence, beaconing, and the ability to retrieve and run additional payloads via a custom scripting language.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.