ATT&CKCampaignsCostaRicto

CostaRicto

C0004

Campaign, Oct 2019 to Nov 2020.View on attack.mitre.org

About this campaign

CostaRicto was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. CostaRicto actors targeted organizations in Europe, the Americas, Asia, Australia, and Africa, with a large concentration in South Asia (especially India, Bangladesh, and Singapore), using custom malware, open source tools, and a complex network of proxies and SSH tunnels.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1005
Data from Local System

During CostaRicto, the threat actors collected data and files from compromised networks.

T1046
Network Service Discovery

During CostaRicto, the threat actors employed nmap and pscan to scan target environments.

T1053.005
Scheduled Task

During CostaRicto, the threat actors used scheduled tasks to download backdoor tools.

T1090.003
Multi-hop Proxy

During CostaRicto, the threat actors used a layer of proxies to manage C2 communications.

T1105
Ingress Tool Transfer

During CostaRicto, the threat actors downloaded malware and tools onto a compromised host.

T1133
External Remote Services

During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment.

T1572
Protocol Tunneling

During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain.

T1583.001
Domains

For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains.

T1587.001
Malware

For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT.

T1588.002
Tool

During CostaRicto, the threat actors obtained open source tools to use in their operations.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software6

References1

  1. BlackBerry CostaRicto November 2020 Open source
    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.