Cobian RAT
MITRE ATT&CK: S0338 View on attack.mitre.org
Aliases: Cobian RAT
- First seen
- 2016-01-01 00:00:00
- Malware type
- rat, backdoor
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 9 (9 malicious)
- Last IoC activity
- 2026-05-08 13:54:42
- Profile updated
- 2026-07-07 15:46:24
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
Cobian RAT is a backdoor, remote access tool that has been observed since 2016.
Recent IoC activity
9 malicious indicators in Maltiverse are attributed to Cobian RAT (S0338). The 9 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | dwupdate.EXE | 2026-05-08 | 1 |
| file sample | hhhhh.exe | 2026-05-08 | 1 |
| file sample | SecuriteInfo.com.W32.AIDetectNet.01.12851.4435 | 2026-04-16 | 1 |
| file sample | 8325ff9c585668aafee7499983616920d347b6e778c5c183484cb0aa5738f45d.exe | 2026-04-12 | 3 |
| file sample | bddf74962e855ed859e0ab4944c1c4242024557d9e160cdd523010245152f83a | 2026-04-03 | 2 |
| file sample | CobianRAT v1.0.40.7.exe | 2026-03-30 | 3 |
| file sample | CobianRAT v1.0.40.7.rar | 2026-03-04 | 1 |
| file sample | 1043faf46b5a19cbe10410e01725b38caf0db7f36b73c68e103ebca8da2d18d2 | 2025-08-31 | 2 |
| file sample | CobianRAT_v1.0.40.7.zip | 2024-10-02 | 1 |
Detection coverage
- 91 Sigma rules
Malware & tools used
- Screen Capture (attack-pattern)
- Video Capture (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Command Shell (attack-pattern)
- Keylogging (attack-pattern)
- DNS (attack-pattern)
- Audio Capture (attack-pattern)
- Standard Encoding (attack-pattern)
Reports & references
- yoroi.company — The Wayback Campaign A Large Scale Operation Hiding In Plain Sight (report)
- cocomelonc.github.io — Malware Pers 1 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Cobian Rat (report)
- securityaffairs.co — Cobian Rat Backdoor (report)
- zscaler.com — Cobian Rat Backdoored Rat (report)
- MITRE ATT&CK — S0338 (report)