SombRAT is a modular Windows remote access trojan associated with the mercenary threat group CostaRicto and also observed in intrusions linked to UNC2447 alongside FiveHands ransomware. It is designed to provide persistent remote access and to securely download, load, and execute additional plugins on compromised systems. The malware has been delivered in spearphishing campaigns and has also appeared in intrusion chains involving exploitation of SonicWall vulnerabilities and post-compromise deployment by operators.
SombRAT uses a plugin-based architecture implemented as cooperating components for core control, networking, storage, task management, and debugging. It supports loading executable modules from disk, storage, or memory, including DLL injection and reflective in-memory execution, enabling flexible post-exploitation without relying solely on files written to disk. Observed loader chains include PowerShell-based, fileless execution that decrypts and reflectively loads the malware into memory while bypassing antimalware scanning interfaces.
The malware performs host reconnaissance and operator tasking functions including process enumeration, service enumeration, collection of the current username, current process, operating system version, and local system time. It can collect and stage files and other data from compromised hosts, store harvested material in temporary local storage, upload collected data to command-and-control infrastructure, and remove staged files after use. It also includes self-respawn and cleanup functionality, allowing it to relaunch itself and delete temporary storage artifacts.
SombRAT protects command-and-control traffic with layered cryptography, including SSL/TLS and additional asymmetric and symmetric encryption. It has been documented using RSA keys and AES-encrypted communications, and it supports multiple command-and-control transports including TLS-encrypted TCP, DNS tunneling, and embedded SOCKS proxy functionality. It can also generate randomized subdomains for command-and-control operations.
Operationally, SombRAT has been used as a stealthy post-compromise backdoor in financially motivated and espionage-oriented activity. In ransomware-linked intrusions, it has supported information theft, staging, and broader hands-on-keyboard operations prior to extortion. Its modular design, in-memory loading, encrypted communications, and plugin execution model make it a versatile platform for reconnaissance, exfiltration, defense evasion, and sustained access in enterprise Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
“CVE-2021-20016 is a critical SQL injection vulnerability that exploits unpatched SonicWall Secure Mobile Access SMA 100 series remote access products… Successful exploitation would grant an attacker the ability to access login credentials (username, password) as well as session information… This vulnerability only impacted the SMA 100 series and was patched by SonicWall in February 2021.”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For many of its campaigns, CostaRicto uses spear-phishing attacks to drop a custom backdoor, dubbed SombRAT, that has rarely been seen in the wild.
Mandiant has observed an aggressive financially motivated group, UNC2447, exploiting one SonicWall VPN zero-day vulnerability prior to a patch being available and deploying sophisticated malware previously reported by other vendors as SOMBRAT.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The newly decoded script is then executed using the InvokeExpression command.
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The RAT has been obfuscated using the XOR key ... The malware contains numerous encoded strings, including an AES key that is used to decrypt the malware configuration file. | This artifact is a Base64 encoded PowerShell script... Next, the script decodes the file "WwanSvc.c" ... using a bitwise Exclusive OR (XOR) with a 256 byte key that is found in WwanSvc.a
Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe... BlackEnergy injects its DLL component into svchost.exe... ComRAT has injected its orchestrator DLL into explorer.exe... Stuxnet injects an entire DLL into an existing, newly created, or preselected trusted process.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The primary purpose of the loader is to allow a remote operator to securely download and load executable plugins ... utilize to secure its command and control (C2) sessions ... encrypted using Advanced Encryption Standard (AES) resulting in a secure Secure Sockets Layer (SSL) tunnel
The program attempts DNS queries for this domain prepending a third level domain that consists of seven to nine random hexidecimal characters, e.g. bb95058f1.feticost.com.
The program also contains native C2 capabilities allowing it to communicate with the remote operator using an embedded SOCKS proxy or via domain name system (DNS) tunneling.
"Anchor has used ICMP in C2 communications." / "COATHANGER uses ICMP for transmitting configuration information..." / "PHOREAL communicates via ICMP for C2." / "Regin ... can use ICMP to communicate between infected computers." / "Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom backdoor used by CostaRicto in spear-phishing campaigns; multiple versions suggest it is adaptable for different attacks.
Remote access trojan that executes getinfo to identify the username on a compromised host.
Enterprise New Software: ... SombRAT
Remote access trojan that can remove stored files and delete temporary storage files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.