Malware.View on attack.mitre.org
CostaBricks is a loader that was used to deploy 32-bit backdoors in the CostaRicto campaign.
| Technique | Procedure example |
|---|---|
| T1027.001 Binary Padding |
CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code. |
| T1027.002 Software Packing |
CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code. |
| T1055 Process Injection |
CostaBricks can inject a payload into the memory of a compromised host. |
| T1105 Ingress Tool Transfer |
CostaBricks has been used to load SombRAT onto a compromised host. |
| T1106 Native API |
CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`. |
| T1140 Deobfuscate/Decode Files or Information |
CostaBricks has the ability to use bytecode to decrypt embedded payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.