CobaltMirage FRP

First seen
2022-03-15 00:00:00
Malware type
trojan
Profile updated
2026-07-07 12:53:27

Targeted industries: financial-services government-and-public-sector

Context

This Go written malware was observed during campaign of COBALT MIRAGE; it includes FRP (Fast Reverse Proxy) published by fatedier on GitHub (https://github.com/fatedier/frp) and other projects additionally.

Reports & references

  • secureworks.com — Cobalt Mirage Conducts Ransomware Operations In Us (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cobaltmirage Tunnel (report)
  • deepinstinct.com — Iranian Threat Actor Continues To Develop Mass Exploitation Tools (report)

External references