Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Briba

Briba

TLP:CLEAR
Family

Also known as: Sharky RAT, Briba, Comfoo

AI Analysis

· 16 hours ago

Executive Summary

Briba is a Windows Trojan associated with the Elderwood botnet that opens a persistent backdoor and downloads arbitrary files to infected hosts. Its modular design enables adversaries to upgrade or pivot payloads through an existing command‑and‑control channel, making it difficult to detect via signatures alone. Security teams should monitor for unusual outbound connections and block known download behaviors to mitigate the threat.

Enhanced Description

Briba is a Windows‑targeted Trojan that operates as a remote access trojan (RAT) for the Elderwood botnet. The malware opens a persistent backdoor on infected hosts, allowing adversaries to upload and execute arbitrary payloads from the command‑and‑control infrastructure. According to Symantec reports dated May and September 2012, Briba downloads files onto compromised machines in order to expand its foothold or install additional malicious components. In addition to remote control capabilities, Briba appears to establish a communication channel with the Elderwood C&C servers, likely using standard HTTP or HTTPS protocols to blend in with legitimate traffic. The backdoor persists by maintaining an active listening socket, enabling continuous reconnaissance and lateral movement across internal networks. While the exact persistence mechanisms are not fully documented, similar variants of the Briba family have been observed creating scheduled tasks and modifying registry keys to restart upon reboot. Briba’s use within the Elderwood ecosystem demonstrates a modular architecture where the initial trojan payload can be upgraded or pivoted by the adversary without requiring re‑infection. This allows operators to adapt quickly to defensive measures, as new downloaders are pushed over the existing backdoor to bypass signature‑based detection.

Key Capabilities

  • Establishes a persistent Windows backdoor
  • Downloads arbitrary files onto infected hosts
  • Communicates with Elderwood C&C servers via HTTP/HTTPS
  • Provides remote command execution through a RAT interface

ATT&CK Techniques

T1059
T1105
T1071

Recommended Actions

  • Block outbound connections to known Elderwood C&C IP addresses or domains
  • Deploy endpoint detection that alerts on unknown process creation and rapid file download activity
  • Use host‑based intrusion prevention to terminate Briba binary execution
  • Ensure antivirus signatures are updated and enable real‑time scanning of downloaded files
  • Review compromised hosts for persistence mechanisms such as scheduled tasks or registry modifications

Suggested Tags

trojan
RAT
backdoor
download
Elderwood
C&C
Windows

Confidence Assessment

The data is based solely on Symantec’s observations from 2012, with limited publicly disclosed technical details. Confidence in the basic description (backdoor behavior, file download) is high, but there is uncertainty regarding specific command protocols, persistence techniques, and lateral movement methods employed by Briba variants.

Description

Briba is a trojan used by Elderwood to open a backdoor and download files on to compromised hosts. (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Briba May 2012)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.