Cotx RAT
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Vulnerabilities exploited
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Attackers relied on Microsoft Equation Editor exploit CVE-2018-0798 to deliver a custom malware that Proofpoint researchers have dubbed Cotx RAT.
攻撃者はEternal Blueを悪用して同一ネットワーク上のいくつかのホストに移動することに成功すると、そのうちの1つのホスト上で興味深いマルウェアを動かし始めました。
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
彼らはPoison IvyやCotx RATを使ってコンピュータのコントロールを得た後、更に侵害を深めるために横展開を行いました。
Techniques & procedures
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
We determined that the infection vector observed in this campaign was spear phishing, with emails originating from both free email accounts and compromised user accounts. Spear phishing emails included malicious .doc attachments that were actually RTF files saved with .doc file extensions. | Proofpoint researchers initially identified email campaigns with malicious RTF document attachments targeting East Asian government agencies in March 2019.
Execution
3 techniques
Execution
We observed the following commands: 5 - Open command shell 6 - Open command shell as logged in user 7 - Send command to command shell
Persistence
2 techniques
Persistence
Privilege Escalation
1 technique
Privilege Escalation
Stealth
3 techniques
Stealth
Spear phishing emails included malicious .doc attachments that were actually RTF files saved with .doc file extensions.
Defense Impairment
1 technique
Defense Impairment
Discovery
5 techniques
Discovery
The initial beacon contains “|”-delimited system information... Computer name... Username... Windows version... Architecture... Local IP addresses... First adapter's MAC address
We observed the following commands: 2 - Get directory info or drive info
Lateral Movement
1 technique
Lateral Movement
Collection
1 technique
Collection
Command and Control
3 techniques
Command and Control
The command and control structure of Cotx RAT is proxy aware. It utilizes wolfSSL for TLS encrypted communication.
IOCs tracked for this family
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
攻撃者がコンピュータの制御を得るために使用したRAT。
Custom remote access trojan written in C++ and delivered via malicious RTF/Equation Editor exploitation. It is side-loaded through RasTls.dll, stores encrypted configuration in a .cotx PE section and the registry, communicates over TLS via proxy-aware C2, and supports commands including shell access, file operations, screenshots, process control, configuration updates, and self-removal.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.