Drokbk is a custom .NET backdoor used by an Iranian state-aligned threat cluster tracked as COBALT MIRAGE Cluster B and also associated in overlapping reporting with Mint Sandstorm, PHOSPHORUS, Charming Kitten, APT35, and Nemesis Kitten. It has been observed since 2022 as a post-intrusion implant used to maintain access on compromised Windows systems and to retrieve additional tooling.
The malware is composed of an installer or dropper and a secondary payload. The dropper establishes persistence by installing the payload as a Windows service, after which the payload operates as the primary implant. Drokbk has limited native functionality and is primarily designed to beacon to operator-controlled infrastructure, receive commands, and execute additional code or tools. Reporting also describes it as being used to download further tooling, and Microsoft has grouped it with Soldier as a custom implant family used for persistence and follow-on tool deployment.
A notable feature of Drokbk is its use of a dead drop resolver technique. Rather than relying solely on a hardcoded command-and-control endpoint, the payload queries GitHub to locate repository content that contains updated command-and-control information. This allows operators to rotate infrastructure while blending traffic with legitimate web services and complicating static detection. After resolving its active infrastructure, the implant sends an initial beacon with basic host information and awaits tasking.
Drokbk has been linked to intrusions against high-value organizations, including U.S. critical infrastructure and a U.S. local government environment. Observed victim sectors include energy and transportation, with broader activity against seaports, transit systems, utilities, and gas-related entities. It has been deployed after exploitation of internet-facing applications, including campaigns leveraging Log4Shell against VMware Horizon and other rapid weaponization of public proof-of-concept exploits by the associated threat actor.
Operationally, Drokbk fits into a broader intrusion set characterized by exploitation of exposed services, PowerShell-based discovery, credential theft, lateral movement, scheduled-task or service-based persistence, and use of additional remote-access tooling. Its role is best understood as a persistence and command-and-control implant that supports sustained access and post-compromise operations in targeted environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2022, Microsoft has observed this Mint Sandstorm subgroup using two custom implants, detected by Microsoft security products as Drokbk and Soldier, to persist in target environments and deploy additional tools.
Since 2022, Microsoft has observed this Mint Sandstorm subgroup using two custom implants, detected by Microsoft security products as Drokbk and Soldier, to persist in target environments and deploy additional tools.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the information from README.md, SessionService.exe sends an initial request to the C2 server. The request contains the hostname and current time.
The Drokbk backdoor issues a web request to obtain the contents of a README file on a Mint Sandstorm-controlled GitHub repo.
Drobkbk and Soldier both use Mint Sandstorm-controlled GitHub repositories to host a domain rotator containing the operators’ C2 domains.
Drokbk uses the dead drop resolver technique to determine its C2 server by connecting to a legitimate service on the internet (e.g., GitHub).
Forensic artifacts indicated Drokbk.exe was extracted from a compressed archive (Drokbk.zip) hosted on the legitimate transfer.sh online service.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in passing via an external Secureworks article title about malware using GitHub as a dead drop resolver; no further behavior details are provided in the content.
Backdoor delivered via GitHub as a conduit in an Iranian nation-state-linked campaign (late 2022 reference).
A .NET malware consisting of a dropper and payload that provides persistence and remote command execution capability. It has limited built-in functionality, uses a dead drop resolver via GitHub to locate its C2 server, and is deployed post-intrusion alongside other access mechanisms as an additional form of persistence.
A custom Charming Kitten implant mentioned as part of the group's broader malware arsenal.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.