ComRAT

S0126

Malware.View on attack.mitre.org

About this malware

ComRAT is a second stage implant suspected of being a descendant of Agent.btz and used by Turla. The first version of ComRAT was identified in 2007, but the tool has undergone substantial development for many years since.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1012
Query Registry

ComRAT can check the default browser by querying HKCR\http\shell\open\command.

T1027
Obfuscated Files or Information

ComRAT has encrypted its virtual file system using AES-256 in XTS mode.

T1027.009
Embedded Payloads

ComRAT has embedded a XOR encrypted communications module inside the orchestrator module.

T1027.010
Command Obfuscation

ComRAT has used encryption and base64 to obfuscate its orchestrator code in the Registry. ComRAT has also used encoded PowerShell scripts.

T1027.011
Fileless Storage

ComRAT has stored encrypted orchestrator code and payloads in the Registry.

T1029
Scheduled Transfer

ComRAT has been programmed to sleep outside local business hours (9 to 5, Monday to Friday).

T1036.004
Masquerade Task or Service

ComRAT has used a task name associated with Windows SQM Consolidator.

T1053.005
Scheduled Task

ComRAT has used a scheduled task to launch its PowerShell loader.

T1055.001
Dynamic-link Library Injection

ComRAT has injected its orchestrator DLL into explorer.exe. ComRAT has also injected its communications module into the victim's default browser to make C2 connections appear less suspicious as all network connections will be initiated by the browser process.

T1059.001
PowerShell

ComRAT has used PowerShell to load itself every time a user logs in to the system. ComRAT can execute PowerShell scripts loaded into memory or from the file system.

T1059.003
Windows Command Shell

ComRAT has used cmd.exe to execute commands.

T1071.001
Web Protocols

ComRAT has used HTTP requests for command and control.

T1071.003
Mail Protocols

ComRAT can use email attachments for command and control.

T1102.002
Bidirectional Communication

ComRAT has the ability to use the Gmail web UI to receive commands and exfiltrate information.

T1106
Native API

ComRAT can load a PE file from memory or the file system and execute it with CreateProcessW.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. ESET ComRAT May 2020 Open source
    Faou, M. (2020, May). From Agent.btz to ComRAT v4: A ten-year journey. Retrieved June 15, 2020.
  2. NorthSec 2015 GData Uroburos Tools Open source
    Rascagneres, P. (2015, May). Tools used by the Uroburos actors. Retrieved August 18, 2016.
  3. Symantec Waterbug Open source
    Symantec. (2015, January 26). The Waterbug attack group. Retrieved April 10, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.