Drokbk is a custom .NET backdoor for Windows used by Iranian government-sponsored operators, including COBALT MIRAGE Cluster B and a mature subgroup tracked by Microsoft as Mint Sandstorm. Observed since 2022, it is deployed after initial compromise to maintain access and execute additional commands or code received from command-and-control infrastructure. Its native functionality is limited, with operators relying on it to download and deploy additional tooling.
The malware consists of an installer or dropper and a secondary backdoor payload. The dropper extracts an embedded payload, installs it as a Windows service for persistence, and removes its temporary installation artifact. The payload uses GitHub as a dead drop resolver: it queries the GitHub API to locate an operator-controlled repository and retrieves command-and-control information from the repository's README. This separates the implant from a fixed command-and-control address and allows operators to rotate infrastructure without replacing the installed malware. After resolving its command-and-control destination, the payload sends an initial beacon containing the infected host's hostname and current time.
Drokbk was observed in a February 2022 intrusion into a U.S. local government network following exploitation of a VMware Horizon server through Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046. Operators deployed it alongside other remote-access mechanisms to provide additional persistence. Its associated Mint Sandstorm subgroup has also targeted high-value energy and transportation organizations and U.S. critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Similarly, Drokbk malware uses the GitHub API to parse a specific repository file to locate and re-establish its C2 connection.”
Since 2022, Microsoft has observed this Mint Sandstorm subgroup using two custom implants, detected by Microsoft security products as Drokbk and Soldier, to persist in target environments and deploy additional tools.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the information from README.md, SessionService.exe sends an initial request to the C2 server. The request contains the hostname and current time.
The Drokbk backdoor issues a web request to obtain the contents of a README file on a Mint Sandstorm-controlled GitHub repo.
Drobkbk and Soldier both use Mint Sandstorm-controlled GitHub repositories to host a domain rotator containing the operators’ C2 domains.
Drokbk uses the dead drop resolver technique to determine its C2 server by connecting to a legitimate service on the internet (e.g., GitHub).
Forensic artifacts indicated Drokbk.exe was extracted from a compressed archive (Drokbk.zip) hosted on the legitimate transfer.sh online service.
27 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a comparison in the attribution discussion: it uses GitHub as a dead-drop resolver to locate and restore C2 communication. The reference does not identify it as a payload deployed in Blinder Tunnel.
Referenced in passing via an external Secureworks article title about malware using GitHub as a dead drop resolver; no further behavior details are provided in the content.
Backdoor delivered via GitHub as a conduit in an Iranian nation-state-linked campaign (late 2022 reference).
A .NET malware consisting of a dropper and payload that provides persistence and remote command execution capability. It has limited built-in functionality, uses a dead drop resolver via GitHub to locate its C2 server, and is deployed post-intrusion alongside other access mechanisms as an additional form of persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.