Cobian RAT is a Windows remote access trojan publicly advertised in underground forums and notable for having been distributed as a backdoored builder. It has been described as broadly similar to njRAT and H-Worm, providing operators with remote control and surveillance functions on infected systems. Documented capabilities include keylogging, screen capture, webcam access, voice recording, remote command shell execution, and execution of attacker-supplied code. It also establishes persistence through a Windows autostart Registry entry and obfuscates command-and-control communications with Base64 encoding.
A distinctive aspect of Cobian RAT is that the builder itself contained a concealed malicious component controlled by the original author. That hidden functionality enabled the author to seize control of systems infected by downstream operators using the builder, effectively backdooring the malware-as-distributed. Reporting has indicated this mechanism allowed the original author to appropriate infected hosts and potentially deny access to the operators who initially deployed the RAT, consistent with an attempt to aggregate a larger botnet through other criminals’ distribution efforts.
Cobian RAT is therefore best understood as both a commodity surveillance-oriented RAT and a supply-chain-style betrayal within the criminal ecosystem, combining standard remote administration and collection features with covert author-controlled takeover of victim machines infected by secondary actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
it implements common spying features such as keylogger, webcam hijacker, screen capturing and of course the ability to execute attackers’ code on the victim’s system.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Cobian RAT obfuscates communications with the C2 server using Base64 encoding... Daserf uses custom base64 encoding to obfuscate HTTP traffic... Pikabot uses base64 encoding in conjunction with symmetric encryption mechanisms to obfuscate command and control communications.
the backdoor module hidden in the Cobian builder kit communicates with a preset page on Pastebin
ADVSTORESHELL C2 traffic is encrypted, then encoded with Base64 encoding. APT19 HTTP malware variant used Base64 to encode communications to the C2 server. APT33 has used base64 to encode command and control traffic.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan that ensures persistence via an autostart Registry key.
Remote access trojan that obfuscates command-and-control communications with Base64.
Remote access trojan with screen capture functionality.
Remote access trojan with screen capture functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.