Agent.btz
MITRE ATT&CK: S0092 View on attack.mitre.org
Aliases: ComRAT, Minit, Sun rootkit, Agent.btz
- Malware type
- worm, rootkit
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:38:47
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:us
Context
Agent.btz is a worm that primarily spreads itself via removable devices such as USB drives. It reportedly infected U.S. military networks in 2008.
Detection coverage
- 1 YARA rules
- 109 Sigma rules
Malware & tools used
- System Owner/User Discovery (attack-pattern)
- Replication Through Removable Media (attack-pattern)
- Exfiltration over USB (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Detection rules
- ARKBIRD_SOLG_APT_Turla_Comrat_Chinch_V4_Jan_2021_1 (yara-rule)
Related threat objects
- ComRAT (malware)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- Broadcom/Symantec — Waterbug Attack Group (report)
- secureworks.com — Iron Hunter (report)
- ESET — Eset Threat Report Q22020 (report)
- ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
- ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
- Kaspersky — 88069 (report)
- crysys.hu — Ukatemicrysys Territorialdispute (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Agent Btz (report)
- ESET — Eset Turla Comrat (report)
- ESET — Eset Jumping The Air Gap Wp (report)
- ESET — Agentbtz Comratv4 Ten Year Journey (report)
- msreverseengineering.com — An Exhaustively Analyzed Idb For Comrat V4 (report)
- artemonsecurity.com — Snake Whitepaper (report)
- blog.gdata.de — 23779 Weiterentwicklung Anspruchsvoller Spyware Von Agent Btz Zu Comrat (report)
- blog.threatexpert.com — Agentbtz Threat That Hit Pentagon (report)
- intezer.com — New Variants Of Agent Btz Comrat Found (report)
- Broadcom/Symantec — Waterbug Attack Group (report)
- CISA — Aa23 129A (report)
- cdn.muckrock.com — 21R019 Response (report)
- Broadcom/Symantec — Waterbug Attack Group 16 En (report)
- ryancor.medium.com — Deobfuscating Powershell Malware Droppers B6C34499E41D (report)
- gdatasoftware.com — 23937 The Uroburos Case New Sophisticated Rat Identified (report)
- blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
- Kaspersky — Agent Btz A Source Of Inspiration (report)