Also known as: Sharky RAT, Briba, Comfoo
Executive Summary
Briba is a Windows Trojan associated with the Elderwood botnet that opens a persistent backdoor and downloads arbitrary files to infected hosts. Its modular design enables adversaries to upgrade or pivot payloads through an existing command‑and‑control channel, making it difficult to detect via signatures alone. Security teams should monitor for unusual outbound connections and block known download behaviors to mitigate the threat.
Enhanced Description
Briba is a Windows‑targeted Trojan that operates as a remote access trojan (RAT) for the Elderwood botnet. The malware opens a persistent backdoor on infected hosts, allowing adversaries to upload and execute arbitrary payloads from the command‑and‑control infrastructure. According to Symantec reports dated May and September 2012, Briba downloads files onto compromised machines in order to expand its foothold or install additional malicious components. In addition to remote control capabilities, Briba appears to establish a communication channel with the Elderwood C&C servers, likely using standard HTTP or HTTPS protocols to blend in with legitimate traffic. The backdoor persists by maintaining an active listening socket, enabling continuous reconnaissance and lateral movement across internal networks. While the exact persistence mechanisms are not fully documented, similar variants of the Briba family have been observed creating scheduled tasks and modifying registry keys to restart upon reboot. Briba’s use within the Elderwood ecosystem demonstrates a modular architecture where the initial trojan payload can be upgraded or pivoted by the adversary without requiring re‑infection. This allows operators to adapt quickly to defensive measures, as new downloaders are pushed over the existing backdoor to bypass signature‑based detection.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The data is based solely on Symantec’s observations from 2012, with limited publicly disclosed technical details. Confidence in the basic description (backdoor behavior, file download) is high, but there is uncertainty regarding specific command protocols, persistence techniques, and lateral movement methods employed by Briba variants.
Briba is a trojan used by Elderwood to open a backdoor and download files on to compromised hosts. (Citation: Symantec Elderwood Sept 2012) (Citation: Symantec Briba May 2012)