Drokbk is a custom .NET malware family consisting of a dropper and a payload, attributed in the provided reporting to COBALT MIRAGE Cluster B, a subgroup of an Iranian government-sponsored threat actor. Microsoft also reported that since 2022 a subgroup it tracks under Mint Sandstorm/Phosphorus has used Drokbk, alongside another implant named Soldier, to achieve persistence on victim machines and download additional tools. Secureworks described Drokbk as having limited native functionality, primarily executing additional commands or code received from command-and-control (C2) infrastructure.
In the reported activity, Drokbk was used post-intrusion to provide persistence in compromised environments. One documented intrusion affecting a U.S. local government network began with exploitation of VMware Horizon via Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046. Forensic artifacts indicated Drokbk.exe was extracted from Drokbk.zip hosted on transfer.sh, written to C:\Users\DomainAdmin\Desktop, and executed.
The dropper checks for C:\ProgramData\SoftwareDistribution and creates it if absent, writes an internal resource to C:\Users\Public\pla as a temporary file, copies that file to C:\ProgramData\SoftwareDistribution\SessionService.exe, creates the Windows service SessionManagerService for persistence using SessionService.exe, and then deletes C:\Users\Public\pla. The main payload, SessionService.exe, begins by locating its C2 domain using a dead drop resolver technique rather than a hardcoded address. Secureworks reported that it used the GitHub API to search for a repository named "mainrepositorytogeta" and retrieved C2 information from the repository README.md; in the observed campaign this was associated with GitHub user Shinault23. Operators rotated C2 servers multiple times between June 9 and July 13, 2022.
After resolving C2 information, SessionService.exe sent an initial beacon containing the infected host's hostname and current time. During execution, Secureworks observed creation of C:\Windows\Temp\v2ggla, C:\Windows\Temp\vdoma434, and C:\ProgramData\Interop Services. Reported Drokbk-related indicators in the provided content include domains activate-microsoft.cf, dns-iprecords.tk, oracle-java.cf, and universityofmhealth.biz, and IP addresses 51.89.135.154, 142.44.149.199, and 142.44.198.202.
The malware is associated with Iranian state-linked operations and has been discussed in the context of activity targeting U.S. local government and, more broadly per Microsoft, U.S. critical infrastructure sectors including seaports, energy companies, transit systems, and a large utility and gas entity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Secureworks® Counter Threat Unit™ (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. This subgroup is known as Cluster B. Drokbk is written in .NET and is made up of a dropper and a payload.
"Further, since 2022, the subgroup has started using two custom .NET implants (dubbed Drokbk and Soldier) to achieve persistence on victim machines and download additional tools."
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Using the information from README.md, SessionService.exe sends an initial request to the C2 server. The request contains the hostname and current time.
Drokbk uses the dead drop resolver technique to determine its C2 server by connecting to a legitimate service on the internet (e.g., GitHub).
Forensic artifacts indicated Drokbk.exe was extracted from a compressed archive (Drokbk.zip) hosted on the legitimate transfer.sh online service.
COBALT MIRAGE's preferred form of remote access uses the Fast Reverse Proxy (FRPC) tool. While COBALT MIRAGE Cluster A uses a modified version of this tool known as TunnelFish, Cluster B favors the unaltered version.
Drokbk uses the dead drop resolver technique to determine its C2 server by connecting to a legitimate service on the internet (e.g., GitHub). The C2 server information is stored on a cloud service in an account that is either preconfigured in the malware or that can be deterministically located by the malware.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered via GitHub as a conduit in an Iranian nation-state-linked campaign (late 2022 reference).
A .NET malware consisting of a dropper and payload that provides persistence and remote command execution capability. It has limited built-in functionality, uses a dead drop resolver via GitHub to locate its C2 server, and is deployed post-intrusion alongside other access mechanisms as an additional form of persistence.
Custom .NET implant used to maintain persistence on victim systems and download additional tooling.
Malware referenced as using GitHub as a dead drop resolver.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.