S0615Windows

S0615SombRAT

Platforms
1
ATT&CK
14.1
References
4

Description

[SombRAT](https://attack.mitre.org/software/S0615) is a modular backdoor written in C++ that has been used since at least 2019 to download and execute malicious payloads, including [FIVEHANDS](https://attack.mitre.org/software/S0618) ransomware.(Citation: BlackBerry CostaRicto November 2020)(Citation: FireEye FiveHands April 2021)(Citation: CISA AR21-126A FIVEHANDS May 2021)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S0615
  2. https://us-cert.cisa.gov/ncas/analysis-reports/ar21-126a
  3. https://www.fireeye.com/blog/threat-research/2021/04/unc2447-sombrat-and-fivehands-ransomware-sophisticated-financial-threat.html
  4. https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
FIVEHANDS
Software
DEATHRANSOM
Software
HELLOKITTY
Software
SDBbot
Software
EVILNUM
Software
QakBot
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.