ComRAT

MITRE ATT&CK: S0126 View on attack.mitre.org

Aliases: ComRAT

First seen
2007-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:46:26

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:de country_code:fr country_code:ru

Context

ComRAT is a second stage implant suspected of being a descendant of Agent.btz and used by Turla. The first version of ComRAT was identified in 2007, but the tool has undergone substantial development for many years since.

Detection coverage

  • 1 YARA rules
  • 502 Sigma rules

Malware & tools used

  • Mail Protocols (attack-pattern)
  • Hidden File System (attack-pattern)
  • Web Protocols (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Software Discovery (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Fileless Storage (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Scheduled Transfer (attack-pattern)
  • Component Object Model Hijacking (attack-pattern)
  • Bidirectional Communication (attack-pattern)
  • Native API (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Query Registry (attack-pattern)
  • PowerShell (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Masquerade Task or Service (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_APT_Turla_Comrat_Chinch_V4_Jan_2021_1 (yara-rule)

Related threat objects

Reports & references

  • threatminer.org — Report (report)
  • ESET — Eset Turla Comrat (report)
  • MITRE ATT&CK — S0126 (report)
  • docplayer.net — 101655589 Tools Used By The Uroburos Actors (report)
  • MITRE ATT&CK — S0126 (report)

External references