Sombrat is a sophisticated malware that poses a significant financial threat, as reported by Mandiant in April 2021. It operates in conjunction with FIVEHANDS Ransomware under the umbrella of UNC2447, a malicious cyber activity group. The malware infects systems through suspicious downloads, emails, or websites, often without the user's knowledge. Once inside a system, it can steal personal information, disrupt operations, or hold data hostage for ransom. This particular variant of malware is notable for its use of a 64-bit SombRAT loader, identifiable through the WwanSvc.b artifact when decoded.
The threat actors behind Sombrat demonstrated advanced techniques to bypass organizational anti-malware programs. They used batch and text files to execute and invoke PowerShell scripts that decoded a SombRAT loader, enabling PowerShell to evade detection. These evasion tactics align with known methods such as Windows Command Shell and PowerShell scripting interpreters, as well as general defense evasion strategies, as outlined in MITRE ATT&CK framework.
Sombrat exhibits unique characteristics that distinguish it from other malware types. It uses RSA for C2 encryption, HTTP for C2 communication, and a custom storage file. It also employs specific decryption and string decoding scripts for its payload. The malware is designed to be downloaded via the SombRAT loader, which is detected by code similarity. These features underscore the sophistication of Sombrat, making it a formidable threat to financial institutions and other potential targets.
Description last updated: 2024-05-04T22:29:02.051Z