RMM

RemSupp

RemSupp is a remote desktop / remote support tool observed in a phone-based social engineering phishing attack. It installs in user context, creates RemSupp-specific artifacts under AppData, and communicates with api.remsupp.com.

Tool overview

Category
RMM
Research authors
Not recorded
Created
2026-04-10
Last modified
2026-05-04
Privileges
User
Free / availability
unknown
Verification required
Installer digitally signed; signer subject "CN=RemSupp Michał Zarach, O=RemSupp Michał Zarach, L=Gdańsk, ST=Pomorskie, C=PL" issued under Microsoft Trusted Signing (CN=Microsoft ID Verified CS EOC CA 0*, O=Microsoft Corporation). Trusted Signing mints ephemeral 3-day leaf certs per signing event, so the leaf TBS hash rotates per release while the publisher subject DN is stable.
Supported platforms
Windows

Capabilities

Remote desktopRemote supportRemote controlScreen sharingFile transfer

Executables & installation paths

Filename
RemSupp_Setup_x64.exe
OriginalFileName
Not recorded
Description
RemSupp - Remote desktop software
Product
RemSupp
Filename
RemSupp.exe
OriginalFileName
RemSupp.exe
Description
RemSupp - Remote desktop software
Product
RemSupp

Installation paths

C:\Users\*\AppData\Local\remsupp-updater\installer.exe
C:\Users\*\AppData\Local\Programs\RemSupp\RemSupp.exe
C:\Users\*\AppData\Local\Programs\RemSupp\Uninstall RemSupp.exe

FORENSIC EVIDENCE

Disk artifacts

File
C:\Users\*\AppData\Local\Programs\RemSupp\RemSupp.exe
Description
Main RemSupp executable (Electron 36 / Chromium-based)
OS
Windows
File
C:\Users\*\AppData\Local\Programs\RemSupp\Uninstall RemSupp.exe
Description
RemSupp uninstaller
OS
Windows
File
C:\Users\*\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RemSupp.lnk
Description
Start menu shortcut
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\Local State
Description
Application local state file
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\Preferences
Description
Application preferences file
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\chromium.log
Description
Chromium log file
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\Crashpad\metadata
Description
Crashpad metadata
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\Crashpad\settings.dat
Description
Crashpad settings
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\Local Storage\leveldb\*
Description
Local storage LevelDB artifacts
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\sentry\queue\queue.json
Description
Sentry queue artifact
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\sentry\scope_v3.json
Description
Sentry scope artifact
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\sentry\session.json
Description
Sentry session artifact
OS
Windows
File
C:\Users\*\AppData\Roaming\RemSupp\quitAndInstall.json
Description
Updater state artifact
OS
Windows

FORENSIC EVIDENCE

Registry artifacts

Path
HKCU\Software\99ac595d-36d0-5122-a860-22a3443073cb
Description
Product-specific installer key (vendor-assigned GUID)
Path
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\99ac595d-36d0-5122-a860-22a3443073cb
Description
Per-user uninstall key (vendor-assigned GUID)

FORENSIC EVIDENCE

Network artifacts

Description
RemSupp API endpoint observed during analysis
Domains
  • api.remsupp.com
Ports
  • 443
Description
RemSupp installer / update download endpoint
Domains
  • download.remsupp.com
Ports
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
CodeSigningSubject
Value
CN=RemSupp Michał Zarach, O=RemSupp Michał Zarach, L=Gdańsk, ST=Pomorskie, C=PL
Type
CodeSigningIssuer
Value
CN=Microsoft ID Verified CS EOC CA 01, O=Microsoft Corporation, C=US
Type
CodeSigningIssuer
Value
CN=Microsoft ID Verified CS EOC CA 02, O=Microsoft Corporation, C=US
Type
ProcessLineage
Value
RemSupp.exe self-check via cmd.exe /c tasklist /FI "USERNAME eq %USERNAME%" /FI "IMAGENAME eq RemSupp.exe" /FO csv | find "RemSupp.exe"
Type
SHA256
Value
994f537e69f555a6aca89db837f260aa31352d6c6bfe435d3ecafff0b8c683ae
Type
SHA256
Value
38a3e51bf0fad50dc3bb08f8ce9aa4e9d3f3c7561312605c6827a81984137532
Type
SHA256
Value
3cad287fbc89c40a4f481aac47d0c2b012388081c9924c09fdb2d29e5455100a

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remsupp_files_sigma.yml
Description
Detects potential files activity of RemSupp RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remsupp_network_sigma.yml
Description
Detects potential network activity of RemSupp RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remsupp_processes_sigma.yml
Description
Detects potential processes activity of RemSupp RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/remsupp_registry_sigma.yml
Description
Detects potential registry activity of RemSupp RMM tool

References

Acknowledgements

Person
Martha Sosa
Handle
@marthajsosa