ATT&CKSoftwareCostaBricks

CostaBricks

S0614

Malware.View on attack.mitre.org

About this malware

CostaBricks is a loader that was used to deploy 32-bit backdoors in the CostaRicto campaign.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.001
Binary Padding

CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code.

T1027.002
Software Packing

CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code.

T1055
Process Injection

CostaBricks can inject a payload into the memory of a compromised host.

T1105
Ingress Tool Transfer

CostaBricks has been used to load SombRAT onto a compromised host.

T1106
Native API

CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`.

T1140
Deobfuscate/Decode Files or Information

CostaBricks has the ability to use bytecode to decrypt embedded payloads.

Groups that use it0

None recorded.

Campaigns1

References1

  1. BlackBerry CostaRicto November 2020 Open source
    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.