Cobian RAT

MITRE ATT&CK: S0338 View on attack.mitre.org

Aliases: Cobian RAT

First seen
2016-01-01 00:00:00
Malware type
rat, backdoor
Family
Malware family
Operating systems
windows
Related IoCs
9 (9 malicious)
Last IoC activity
2026-05-08 13:54:42
Profile updated
2026-07-07 15:46:24

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

Cobian RAT is a backdoor, remote access tool that has been observed since 2016.

Recent IoC activity

9 malicious indicators in Maltiverse are attributed to Cobian RAT (S0338). The 9 most recently updated:

TypeIndicatorUpdatedSources
file sample dwupdate.EXE 2026-05-08 1
file sample hhhhh.exe 2026-05-08 1
file sample SecuriteInfo.com.W32.AIDetectNet.01.12851.4435 2026-04-16 1
file sample 8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d.exe 2026-04-12 3
file sample bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a 2026-04-03 2
file sample CobianRAT v1.0.40.7.exe 2026-03-30 3
file sample CobianRAT v1.0.40.7.rar 2026-03-04 1
file sample 1043faf46b5a19cbe10410e01725b38caf0db7f36b73c68e103ebca8da2d18d2 2025-08-31 2
file sample CobianRAT_v1.0.40.7.zip 2024-10-02 1

Detection coverage

  • 91 Sigma rules

Malware & tools used

  • Screen Capture (attack-pattern)
  • Video Capture (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Keylogging (attack-pattern)
  • DNS (attack-pattern)
  • Audio Capture (attack-pattern)
  • Standard Encoding (attack-pattern)

Reports & references

  • yoroi.company — The Wayback Campaign A Large Scale Operation Hiding In Plain Sight (report)
  • cocomelonc.github.io — Malware Pers 1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cobian Rat (report)
  • securityaffairs.co — Cobian Rat Backdoor (report)
  • zscaler.com — Cobian Rat Backdoored Rat (report)
  • MITRE ATT&CK — S0338 (report)

External references