Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
MalwareCobian RAT | Cobian RAT has a feature to perform keylogging on the victim’s machine. |
| T1059.003 Windows Command Shell |
MalwareCobian RAT | Cobian RAT can launch a remote command shell interface for executing commands. |
| T1071.004 DNS |
MalwareCobian RAT | Cobian RAT uses DNS for C2. |
| T1113 Screen Capture |
MalwareCobian RAT | Cobian RAT has a feature to perform screen capture. |
| T1123 Audio Capture |
MalwareCobian RAT | Cobian RAT has a feature to perform voice recording on the victim’s machine. |
| T1125 Video Capture |
MalwareCobian RAT | Cobian RAT has a feature to access the webcam on the victim’s machine. |
| T1132.001 Standard Encoding |
MalwareCobian RAT | Cobian RAT obfuscates communications with the C2 server using Base64 encoding. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareCobian RAT | Cobian RAT creates an autostart Registry key to ensure persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.