ATT&CKReferencesZscaler Cobian Aug 2017

Zscaler Cobian Aug 2017

Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareCobian RAT

Cobian RAT has a feature to perform keylogging on the victim’s machine.

T1059.003
Windows Command Shell
MalwareCobian RAT

Cobian RAT can launch a remote command shell interface for executing commands.

T1071.004
DNS
MalwareCobian RAT

Cobian RAT uses DNS for C2.

T1113
Screen Capture
MalwareCobian RAT

Cobian RAT has a feature to perform screen capture.

T1123
Audio Capture
MalwareCobian RAT

Cobian RAT has a feature to perform voice recording on the victim’s machine.

T1125
Video Capture
MalwareCobian RAT

Cobian RAT has a feature to access the webcam on the victim’s machine.

T1132.001
Standard Encoding
MalwareCobian RAT

Cobian RAT obfuscates communications with the C2 server using Base64 encoding.

T1547.001
Registry Run Keys / Startup Folder
MalwareCobian RAT

Cobian RAT creates an autostart Registry key to ensure persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.