Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CostaRicto

Description

CostaRicto is a cyber-espionage threat actor that operates as a mercenary group, offering its services to various clients globally. They use bespoke malware tools and sophisticated techniques like VPN proxy and SSH tunnelling. While their targets are scattered across different regions, there is a concentration in South Asia.

AI Analysis

· 1 week ago

Executive Summary

CostaRicto is a mercenary cyber-espionage group operating globally with a focus on South Asia. The group employs sophisticated techniques such as SSH tunnelling and bespoke malware to exfiltrate sensitive information from high-value targets. Their activities suggest alignment with clients seeking strategic intelligence, though their exact motivations remain unclear.

Goals & Targeting

CostaRicto's primary objective appears to be the acquisition of sensitive information for financial or strategic gain, given their mercenary model. Their focus on South Asia suggests an interest in regions with emerging digital economies, critical infrastructure, or political instability that could be exploited for intelligence purposes. Typical victims include organizations in government, energy, and defense sectors, where access to classified or proprietary data would hold significant value to paying clients. The group's lack of overt ideological alignment suggests a transactional approach to targeting, prioritizing client demands over geopolitical motives.

Enhanced Description

CostaRicto operates as a hired cyber-espionage group, offering its services to a diverse set of clients worldwide. The actor leverages custom-developed malware and advanced obfuscation methods, including SSH tunnelling and VPN proxy infrastructure, to maintain operational stealth. While their targeting is geographically dispersed, South Asia has been a focal region, likely due to the presence of strategic sectors such as government, energy, and finance. The group's reliance on bespoke tools and lack of public attribution suggests a high degree of operational autonomy and a focus on avoiding detection. Their tactics indicate a preference for covert, long-term access rather than disruptive attacks, aligning with espionage objectives. However, further analysis is required to fully understand their infrastructure and potential links to other known threat groups.

Key Capabilities

  • Use of custom-developed malware with anti-forensic features
  • SSH tunnelling and VPN proxy techniques for command-and-control (C2) obfuscation
  • Sophisticated network infiltration and lateral movement within compromised environments
  • Targeted spear-phishing campaigns with tailored payloads
  • Data exfiltration using stealthy, encrypted channels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Data Exfiltration

ATT&CK Techniques

T1055.003 - Peer-to-Peer Communication
T1071.001 - Proxy
T1573 - Encrypted Channel
T1059.003 - Command-Line Interface
T1219 - Exploit Public-Facing Application

Software / Tooling

Bespoke Malware (Custom-built tools with no public attribution)
SSH-based tunneling infrastructure
Custom C2 servers with domain generation algorithms (DGAs)

Campaigns & Victims

CostaRicto's campaigns exhibit a low operational tempo but high precision, suggesting a focus on stealth and long-term access. Operations often involve multi-stage implants and staged infrastructure deployment, with a preference for bulletproof hosting services to avoid detection. Notable past activities include targeting South Asian energy firms and diplomatic institutions, though no major publicly known breaches have been directly attributed to the group. Their reliance on manual exploitation techniques and lack of automated tools indicates a highly tailored approach to each operation.

IOC Patterns

  • Spear-phishing emails with macro-laced Microsoft Office documents
  • C2 communication over SSH tunnelling and commercial VPN services
  • Staged infrastructure on bulletproof hosting platforms
  • Domain generation algorithms with geopolitical-related keywords
  • Unusual network traffic patterns during off-peak hours

Recommended Actions

  • Monitor for anomalous SSH and VPN tunneling activity originating from South Asian IP ranges
  • Implement advanced email filtering with sandboxing for malicious document attachments
  • Deploy endpoint detection and response (EDR) tools to identify custom malware behavior
  • Conduct regular network traffic analysis for encrypted channel anomalies
  • Perform red-team exercises targeting South Asian-specific attack vectors

Suggested Tags

APT
cyber-espionage
mercenary-group
south-asia-focused
custom-malware

Confidence Assessment

Confidence in the described capabilities is moderate, based on observed TTPs and limited public reporting. Gaps exist in confirming direct links to specific campaigns, identifying associated malware signatures, and attributing activities to definitive clients. Further analysis of network logs and malware samples from South Asian victims could provide higher confidence in operational details.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
cyber-espionage
mercenary-group
south-asia-focused
custom-malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.