Agent.btz

MITRE ATT&CK: S0092 View on attack.mitre.org

Aliases: ComRAT, Minit, Sun rootkit, Agent.btz

Malware type
worm, rootkit
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:38:47

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:us

Context

Agent.btz is a worm that primarily spreads itself via removable devices such as USB drives. It reportedly infected U.S. military networks in 2008.

Detection coverage

  • 1 YARA rules
  • 109 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Exfiltration over USB (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Detection rules

  • ARKBIRD_SOLG_APT_Turla_Comrat_Chinch_V4_Jan_2021_1 (yara-rule)

Related threat objects

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • Broadcom/Symantec — Waterbug Attack Group (report)
  • secureworks.com — Iron Hunter (report)
  • ESET — Eset Threat Report Q22020 (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • ironnet.com — Russian Cyber Attack Campaigns And Actors (report)
  • Kaspersky — 88069 (report)
  • crysys.hu — Ukatemicrysys Territorialdispute (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Agent Btz (report)
  • ESET — Eset Turla Comrat (report)
  • ESET — Eset Jumping The Air Gap Wp (report)
  • ESET — Agentbtz Comratv4 Ten Year Journey (report)
  • msreverseengineering.com — An Exhaustively Analyzed Idb For Comrat V4 (report)
  • artemonsecurity.com — Snake Whitepaper (report)
  • blog.gdata.de — 23779 Weiterentwicklung Anspruchsvoller Spyware Von Agent Btz Zu Comrat (report)
  • blog.threatexpert.com — Agentbtz Threat That Hit Pentagon (report)
  • intezer.com — New Variants Of Agent Btz Comrat Found (report)
  • Broadcom/Symantec — Waterbug Attack Group (report)
  • CISA — Aa23 129A (report)
  • cdn.muckrock.com — 21R019 Response (report)
  • Broadcom/Symantec — Waterbug Attack Group 16 En (report)
  • ryancor.medium.com — Deobfuscating Powershell Malware Droppers B6C34499E41D (report)
  • gdatasoftware.com — 23937 The Uroburos Case New Sophisticated Rat Identified (report)
  • blogs.vmware.com — Detecting Threats In Real Time With Active C2 Information (report)
  • Kaspersky — Agent Btz A Source Of Inspiration (report)

External references