ATT&CKReferencesBlackBerry CostaRicto November 2020

BlackBerry CostaRicto November 2020

The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns1

Procedure examples42

TechniqueUsed byProcedure example
T1005
Data from Local System
CampaignCostaRicto

During CostaRicto, the threat actors collected data and files from compromised networks.

T1005
Data from Local System
MalwareSombRAT

SombRAT has collected data and files from a compromised host.

T1007
System Service Discovery
MalwareSombRAT

SombRAT can enumerate services on a victim machine.

T1027
Obfuscated Files or Information
MalwareSombRAT

SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.

T1027.001
Binary Padding
MalwareCostaBricks

CostaBricks has added the entire unobfuscated code of the legitimate open source application Blink to its code.

T1027.002
Software Packing
MalwareCostaBricks

CostaBricks can implement a custom-built virtual machine mechanism to obfuscate its code.

T1027.013
Encrypted/Encoded File
MalwarePS1

PS1 is distributed as a set of encrypted files and scripts.

T1033
System Owner/User Discovery
MalwareSombRAT

SombRAT can execute getinfo to identify the username on a compromised host.

T1041
Exfiltration Over C2 Channel
MalwareSombRAT

SombRAT has uploaded collected data and files from a compromised host to its C2 server.

T1046
Network Service Discovery
CampaignCostaRicto

During CostaRicto, the threat actors employed nmap and pscan to scan target environments.

T1053.005
Scheduled Task
CampaignCostaRicto

During CostaRicto, the threat actors used scheduled tasks to download backdoor tools.

T1055
Process Injection
MalwareCostaBricks

CostaBricks can inject a payload into the memory of a compromised host.

T1055.001
Dynamic-link Library Injection
MalwarePS1

PS1 can inject its payload DLL Into memory.

T1055.001
Dynamic-link Library Injection
MalwareSombRAT

SombRAT can execute loadfromfile, loadfromstorage, and loadfrommem to inject a DLL from disk, storage, or memory respectively.

T1057
Process Discovery
MalwareSombRAT

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1059.001
PowerShell
MalwarePS1

PS1 can utilize a PowerShell loader.

T1070.004
File Deletion
MalwareSombRAT

SombRAT has the ability to run cancel or closeanddeletestorage to remove all files from storage and delete the storage temp file on a compromised host.

T1071.004
DNS
MalwareSombRAT

SombRAT can communicate over DNS with the C2 server.

T1074.001
Local Data Staging
MalwareSombRAT

SombRAT can store harvested data in a custom database under the %TEMP% directory.

T1082
System Information Discovery
MalwareSombRAT

SombRAT can execute getinfo to enumerate the computer name and OS version of a compromised system.

T1083
File and Directory Discovery
MalwareSombRAT

SombRAT can execute enum to enumerate files in storage on a compromised system.

T1090.003
Multi-hop Proxy
CampaignCostaRicto

During CostaRicto, the threat actors used a layer of proxies to manage C2 communications.

T1095
Non-Application Layer Protocol
MalwareSombRAT

SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.

T1105
Ingress Tool Transfer
MalwareCostaBricks

CostaBricks has been used to load SombRAT onto a compromised host.

T1105
Ingress Tool Transfer
CampaignCostaRicto

During CostaRicto, the threat actors downloaded malware and tools onto a compromised host.

T1105
Ingress Tool Transfer
MalwareSombRAT

SombRAT has the ability to download and execute additional payloads.

T1105
Ingress Tool Transfer
MalwarePS1

CostaBricks can download additional payloads onto a compromised host.

T1106
Native API
MalwareCostaBricks

CostaBricks has used a number of API calls, including `VirtualAlloc`, `VirtualFree`, `LoadLibraryA`, `GetProcAddress`, and `ExitProcess`.

T1106
Native API
MalwareSombRAT

SombRAT has the ability to respawn itself using ShellExecuteW and CreateProcessW.

T1124
System Time Discovery
MalwareSombRAT

SombRAT can execute getinfo to discover the current time on a compromised host.

T1133
External Remote Services
CampaignCostaRicto

During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment.

T1140
Deobfuscate/Decode Files or Information
MalwarePS1

PS1 can use an XOR key to decrypt a PowerShell loader and payload binary.

T1140
Deobfuscate/Decode Files or Information
MalwareCostaBricks

CostaBricks has the ability to use bytecode to decrypt embedded payloads.

T1140
Deobfuscate/Decode Files or Information
MalwareSombRAT

SombRAT can run upload to decrypt and upload files from storage.

T1560.003
Archive via Custom Method
MalwareSombRAT

SombRAT has encrypted collected data with AES-256 using a hardcoded key.

T1568.002
Domain Generation Algorithms
MalwareSombRAT

SombRAT can use a custom DGA to generate a subdomain for C2.

T1572
Protocol Tunneling
CampaignCostaRicto

During CostaRicto, the threat actors set up remote SSH tunneling into the victim's environment from a malicious domain.

T1573.001
Symmetric Cryptography
MalwareSombRAT

SombRAT has encrypted its C2 communications with AES.

T1573.002
Asymmetric Cryptography
MalwareSombRAT

SombRAT can SSL encrypt C2 traffic.

T1583.001
Domains
CampaignCostaRicto

For CostaRicto, the threat actors established domains, some of which appeared to spoof legitimate domains.

T1587.001
Malware
CampaignCostaRicto

For CostaRicto, the threat actors used custom malware, including PS1, CostaBricks, and SombRAT.

T1588.002
Tool
CampaignCostaRicto

During CostaRicto, the threat actors obtained open source tools to use in their operations.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.