Remexi is a custom Windows backdoor used by the Iran-linked cyberespionage group Chafer, also known as APT39. It supports remote command execution and surveillance of compromised systems, including keystroke logging, clipboard text collection, screenshots of selected windows, and retrieval of active-window titles. It also collects system usernames for victim reconnaissance.
Remexi uses AutoIt and VBScript during execution and can execute operator-supplied WMI commands through the Windows Management Instrumentation command-line utility. It establishes persistence through scheduled tasks and machine-wide registry autostart mechanisms. Its configuration is protected with XOR encryption using 25-character keys. Command-and-control communications and data exfiltration use BITSAdmin, allowing collected information to leave the system over the same channel used for operator communications.
Remexi forms part of Chafer's espionage toolset. The group's targeting has included telecommunications, aviation, travel-related businesses, and government organizations, particularly in the Middle East.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Found as “mas.dll” in our telemetry, it has been previously depicted as a backdoor.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware explicitly listed by Symantec as associated with Chafer attack protections.
Backdoor used to collect usernames from the system.
Uses AutoIt and VBS scripts throughout execution.
Malware that establishes persistence via HKLM Run registry keys.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.