The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
CampaignCostaRicto | During CostaRicto, the threat actors collected data and files from compromised networks. |
| T1005 Data from Local System |
MalwareSombRAT | SombRAT has collected data and files from a compromised host. |
| T1007 System Service Discovery |
MalwareSombRAT | SombRAT can enumerate services on a victim machine. |
| T1027 Obfuscated Files or Information |
MalwareSombRAT | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data. |
| T1027.001 Binary Padding |
MalwareCostaBricks | CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code. |
| T1027.002 Software Packing |
MalwareCostaBricks | CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code. |
| T1027.013 Encrypted/Encoded File |
MalwarePS1 | PS1 is distributed as a set of encrypted files and scripts. |
| T1033 System Owner/User Discovery |
MalwareSombRAT | SombRAT can execute |
| T1041 Exfiltration Over C2 Channel |
MalwareSombRAT | SombRAT has uploaded collected data and files from a compromised host to its C2 server. |
| T1046 Network Service Discovery |
CampaignCostaRicto | During CostaRicto, the threat actors employed nmap and pscan to scan target environments. |
| T1053.005 Scheduled Task |
CampaignCostaRicto | During CostaRicto, the threat actors used scheduled tasks to download backdoor tools. |
| T1055 Process Injection |
MalwareCostaBricks | CostaBricks can inject a payload into the memory of a compromised host. |
| T1055.001 Dynamic-link Library Injection |
MalwarePS1 | PS1 can inject its payload DLL Into memory. |
| T1055.001 Dynamic-link Library Injection |
MalwareSombRAT | SombRAT can execute |
| T1057 Process Discovery |
MalwareSombRAT | SombRAT can use the |
| T1059.001 PowerShell |
MalwarePS1 | PS1 can utilize a PowerShell loader. |
| T1070.004 File Deletion |
MalwareSombRAT | SombRAT has the ability to run |
| T1071.004 DNS |
MalwareSombRAT | SombRAT can communicate over DNS with the C2 server. |
| T1074.001 Local Data Staging |
MalwareSombRAT | SombRAT can store harvested data in a custom database under the %TEMP% directory. |
| T1082 System Information Discovery |
MalwareSombRAT | SombRAT can execute |
| T1083 File and Directory Discovery |
MalwareSombRAT | SombRAT can execute |
| T1090.003 Multi-hop Proxy |
CampaignCostaRicto | During CostaRicto, the threat actors used a layer of proxies to manage C2 communications. |
| T1095 Non-Application Layer Protocol |
MalwareSombRAT | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server. |
| T1105 Ingress Tool Transfer |
MalwareCostaBricks | CostaBricks has been used to load SombRAT onto a compromised host. |
| T1105 Ingress Tool Transfer |
CampaignCostaRicto | During CostaRicto, the threat actors downloaded malware and tools onto a compromised host. |
| T1105 Ingress Tool Transfer |
MalwareSombRAT | SombRAT has the ability to download and execute additional payloads. |
| T1105 Ingress Tool Transfer |
MalwarePS1 | CostaBricks can download additional payloads onto a compromised host. |
| T1106 Native API |
MalwareCostaBricks | CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`. |
| T1106 Native API |
MalwareSombRAT | SombRAT has the ability to respawn itself using |
| T1124 System Time Discovery |
MalwareSombRAT | SombRAT can execute |
| T1133 External Remote Services |
CampaignCostaRicto | During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment. |
| T1140 Deobfuscate/Decode Files or Information |
MalwarePS1 | PS1 can use an XOR key to decrypt a PowerShell loader and payload binary. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCostaBricks | CostaBricks has the ability to use bytecode to decrypt embedded payloads. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSombRAT | SombRAT can run |
| T1560.003 Archive via Custom Method |
MalwareSombRAT | SombRAT has encrypted collected data with AES-256 using a hardcoded key. |
| T1568.002 Domain Generation Algorithms |
MalwareSombRAT | SombRAT can use a custom DGA to generate a subdomain for C2. |
| T1572 Protocol Tunneling |
CampaignCostaRicto | During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain. |
| T1573.001 Symmetric Cryptography |
MalwareSombRAT | SombRAT has encrypted its C2 communications with AES. |
| T1573.002 Asymmetric Cryptography |
MalwareSombRAT | SombRAT can SSL encrypt C2 traffic. |
| T1583.001 Domains |
CampaignCostaRicto | For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains. |
| T1587.001 Malware |
CampaignCostaRicto | For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT. |
| T1588.002 Tool |
CampaignCostaRicto | During CostaRicto, the threat actors obtained open source tools to use in their operations. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.