ATT&CKSoftwareCobian RAT

Cobian RAT

S0338

Malware.View on attack.mitre.org

About this malware

Cobian RAT is a backdoor, remote access tool that has been observed since 2016.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1056.001
Keylogging

Cobian RAT has a feature to perform keylogging on the victim’s machine.

T1059.003
Windows Command Shell

Cobian RAT can launch a remote command shell interface for executing commands.

T1071.004
DNS

Cobian RAT uses DNS for C2.

T1113
Screen Capture

Cobian RAT has a feature to perform screen capture.

T1123
Audio Capture

Cobian RAT has a feature to perform voice recording on the victim’s machine.

T1125
Video Capture

Cobian RAT has a feature to access the webcam on the victim’s machine.

T1132.001
Standard Encoding

Cobian RAT obfuscates communications with the C2 server using Base64 encoding.

T1547.001
Registry Run Keys / Startup Folder

Cobian RAT creates an autostart Registry key to ensure persistence.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Zscaler Cobian Aug 2017 Open source
    Yadav, A., et al. (2017, August 31). Cobian RAT – A backdoored RAT. Retrieved November 13, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.