Executive Summary
CostaBricks is a Windows loader that deploys 32‑bit backdoors as part of the CostaRicto campaign. It delivers payloads via obfuscated code and establishes long‑term persistence, enabling attackers to maintain covert access for lateral movement and data exfiltration.
Enhanced Description
CostaBricks is a lightweight loader designed for Windows platforms that serves primarily as an installer for 32‑bit backdoor components used in the CostaRicto campaign. Once executed on a target host, CostaBricks downloads and deploys additional malicious payloads—often stealthy remote access trojans (RATs) or keyloggers—into system directories or registry locations to facilitate persistence. The loader itself does not perform extensive data exfiltration; instead it establishes an outbound channel to command-and-control (C2) infrastructure, allowing attackers to issue commands, modify the victim’s environment, and acquire sensitive information from the installed backdoors. Operationally, CostaBricks employs obfuscated code and anti‑analysis techniques typical of contemporary threats. It may use encrypted communication or encode payloads in Base64 to bypass signature‑based detection tools. The loader is typically delivered via spear‑phishing attachments, malicious websites, or compromised third‑party software updates, allowing attackers to execute it remotely and trigger the deployment of the full backdoor suite. Over time, defenders have observed repeated use of this same loader across different stages of the CostaRicto campaign, indicating a modular approach that allows substitution of new backdoors without changing the initial delivery mechanism. Impact-wise, infected systems can suffer from data loss, credential theft, lateral movement in enterprise networks, and a long‑term foothold for further exploitation. Because CostaBricks focuses on establishing persistent access rather than immediate sabotage, its presence often goes unnoticed until compromised assets are used by adversaries to exfiltrate corporate secrets or pivot into deeper network segments.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the loader’s function as an installation vehicle is high, based on published threat intel and citation. However, details regarding exact persistence mechanisms, C2 protocols, encryption methods, and variations used across campaign phases remain incomplete.
CostaBricks is a loader that was used to deploy 32-bit backdoors in the CostaRicto campaign.(Citation: BlackBerry CostaRicto November 2020)