SombRAT

S0615

Malware.View on attack.mitre.org

About this malware

SombRAT is a modular backdoor written in C++ that has been used since at least 2019 to download and execute malicious payloads, including FIVEHANDS ransomware.

Techniques used24

Procedure examples24

TechniqueProcedure example
T1005
Data from Local System

SombRAT has collected data and files from a compromised host.

T1007
System Service Discovery

SombRAT can enumerate services on a victim machine.

T1027
Obfuscated Files or Information

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1033
System Owner/User Discovery

SombRAT can execute getinfo to identify the username on a compromised host.

T1036
Masquerading

SombRAT can use a legitimate process name to hide itself.

T1041
Exfiltration Over C2 Channel

SombRAT has uploaded collected data and files from a compromised host to its C2 server.

T1055.001
Dynamic-link Library Injection

SombRAT can execute loadfromfile, loadfromstorage, and loadfrommem to inject a DLL from disk, storage, or memory respectively.

T1057
Process Discovery

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1070.004
File Deletion

SombRAT has the ability to run cancel or closeanddeletestorage to remove all files from storage and delete the storage temp file on a compromised host.

T1071.004
DNS

SombRAT can communicate over DNS with the C2 server.

T1074.001
Local Data Staging

SombRAT can store harvested data in a custom database under the %TEMP% directory.

T1082
System Information Discovery

SombRAT can execute getinfo to enumerate the computer name and OS version of a compromised system.

T1083
File and Directory Discovery

SombRAT can execute enum to enumerate files in storage on a compromised system.

T1090
Proxy

SombRAT has the ability to use an embedded SOCKS proxy in C2 communications.

T1095
Non-Application Layer Protocol

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

View all 24 procedure examples

Groups that use it0

None recorded.

Campaigns1

References3

  1. BlackBerry CostaRicto November 2020 Open source
    The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.
  2. CISA AR21-126A FIVEHANDS May 2021 Open source
    CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021.
  3. FireEye FiveHands April 2021 Open source
    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.