CostaRicto is a mercenary advanced persistent threat group associated with cyber-espionage-for-hire activity. Public reporting has described the group as targeting organizations worldwide, with notable concentration in South Asia and additional victims across Africa, Europe, and the Americas. Victimology has included the financial sector. CostaRicto has been linked to spear-phishing operations and to the use of stolen credentials for access, indicating a flexible intrusion model that combines social engineering with credential-based compromise. The group is known for using custom malware including SombRAT, CostaBricks, and PS1. SombRAT has been characterized as a custom backdoor used in espionage operations. CostaRicto also makes use of open-source and dual-use tooling during intrusions, including network scanning utilities such as Nmap and pscan, and SSH-based tunneling tools to maintain access within compromised environments. Operationally, CostaRicto has demonstrated reconnaissance and scanning of target environments, downloading of additional malware and tools onto compromised hosts, persistence through scheduled tasks, and command-and-control concealment through layered proxy infrastructure. The group has also established spoofed or look-alike domains as part of its operational infrastructure. These behaviors are consistent with a mature intrusion set focused on stealthy access, sustained footholds, and intelligence collection on behalf of clients rather than disruptive or extortion-driven operations. CostaRicto is widely regarded as part of the broader mercenary intrusion ecosystem, sometimes described as hackers-for-hire or private-sector offensive actors. Its activity aligns most closely with espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mercenary APT conducting global intrusion campaigns, especially in South Asia, using spear-phishing and stolen credentials to compromise organizations, with many victims in the financial sector.
Listed as a newly added ATT&CK Enterprise group in the October 2021 (v10) release notes; no operational details provided in this content.
Uses scheduled tasks to download backdoor tooling.
Named campaign/cluster previously associated with SOMBRAT backdoor and described as potential espionage-for-hire activity; in this content, referenced as prior reporting context for SOMBRAT rather than as the primary operator of the ransomware intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.