Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware CostaBricks

CostaBricks

TLP:CLEAR
Family

AI Analysis

· 6 hours ago

Executive Summary

CostaBricks is a Windows loader that deploys 32‑bit backdoors as part of the CostaRicto campaign. It delivers payloads via obfuscated code and establishes long‑term persistence, enabling attackers to maintain covert access for lateral movement and data exfiltration.

Enhanced Description

CostaBricks is a lightweight loader designed for Windows platforms that serves primarily as an installer for 32‑bit backdoor components used in the CostaRicto campaign. Once executed on a target host, CostaBricks downloads and deploys additional malicious payloads—often stealthy remote access trojans (RATs) or keyloggers—into system directories or registry locations to facilitate persistence. The loader itself does not perform extensive data exfiltration; instead it establishes an outbound channel to command-and-control (C2) infrastructure, allowing attackers to issue commands, modify the victim’s environment, and acquire sensitive information from the installed backdoors. Operationally, CostaBricks employs obfuscated code and anti‑analysis techniques typical of contemporary threats. It may use encrypted communication or encode payloads in Base64 to bypass signature‑based detection tools. The loader is typically delivered via spear‑phishing attachments, malicious websites, or compromised third‑party software updates, allowing attackers to execute it remotely and trigger the deployment of the full backdoor suite. Over time, defenders have observed repeated use of this same loader across different stages of the CostaRicto campaign, indicating a modular approach that allows substitution of new backdoors without changing the initial delivery mechanism. Impact-wise, infected systems can suffer from data loss, credential theft, lateral movement in enterprise networks, and a long‑term foothold for further exploitation. Because CostaBricks focuses on establishing persistent access rather than immediate sabotage, its presence often goes unnoticed until compromised assets are used by adversaries to exfiltrate corporate secrets or pivot into deeper network segments.

Key Capabilities

  • Downloads additional malicious payloads
  • Installs 32‑bit backdoor components
  • Establishes outbound C2 channels
  • Uses obfuscation/encoding techniques
  • Permanently persists via system registry or startup items

ATT&CK Techniques

T1105
T1059
T1083
T1027

Recommended Actions

  • Deploy behavioral detection rules that flag unknown loader executables with remote download behavior
  • Use endpoint protection that can detect and block Base64‐encoded code and encrypted payload downloads
  • Block traffic to known CostaBricks C2 IPs/Domain families
  • Implement strong email filtering to mitigate spear‑phishing delivery
  • Set up network monitoring for outbound connections to unfamiliar domains on uncommon ports

Suggested Tags

malware
loader
backdoor
Windows
CostaRicto
CVE exploitation

Confidence Assessment

Confidence in the loader’s function as an installation vehicle is high, based on published threat intel and citation. However, details regarding exact persistence mechanisms, C2 protocols, encryption methods, and variations used across campaign phases remain incomplete.

Description

CostaBricks is a loader that was used to deploy 32-bit backdoors in the CostaRicto campaign.(Citation: BlackBerry CostaRicto November 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.