CostaRicto__2020__The_CostaRicto_Campaign_Cyber-Espionage_Outsourced.pdf
ID: c8270f4b-9dbd-44d8-9a4a-a5ee266e8a7f
STIX ID: report--c8270f4b-9dbd-44d8-9a4a-a5ee266e8a7f
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2020-11-13
Last Modified Date: 2020-11-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The BlackBerry Research and Intelligence report dissects the CostaRicto campaign — an outsourced, mercenary-style cyber‑espionage operation that uses a custom backdoor (SombRAT) and VM-based loader (CostaBricks) delivered via scheduled tasks, PowerShell loaders, and reverse-DNS stagers; it employs DNS tunneling, RSA/AES encryption, SSH tunnelling and proxy layers for C2, targets diverse global victims (notably in South Asia), and includes IoCs (hashes, domains, IPs), YARA hunting rules, IDA Python scripts and MITRE mappings to aid detection and response.
