Campaign, Oct 2019 to Nov 2020.View on attack.mitre.org
CostaRicto was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. CostaRicto actors targeted organizations in Europe, the Americas, Asia, Australia, and Africa, with a large concentration in South Asia (especially India, Bangladesh, and Singapore), using custom malware, open source tools, and a complex network of proxies and SSH tunnels.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
During CostaRicto, the threat actors collected data and files from compromised networks. |
| T1046 Network Service Discovery |
During CostaRicto, the threat actors employed nmap and pscan to scan target environments. |
| T1053.005 Scheduled Task |
During CostaRicto, the threat actors used scheduled tasks to download backdoor tools. |
| T1090.003 Multi-hop Proxy |
During CostaRicto, the threat actors used a layer of proxies to manage C2 communications. |
| T1105 Ingress Tool Transfer |
During CostaRicto, the threat actors downloaded malware and tools onto a compromised host. |
| T1133 External Remote Services |
During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment. |
| T1572 Protocol Tunneling |
During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain. |
| T1583.001 Domains |
For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains. |
| T1587.001 Malware |
For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT. |
| T1588.002 Tool |
During CostaRicto, the threat actors obtained open source tools to use in their operations. |
MITRE does not attribute this campaign to a group.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.