ComRAT campaign

GPTKB entity

Statements (21)
Predicate Object
gptkbp:instanceOf cyber espionage campaign
gptkbp:activeYearsStart at least 2007
gptkbp:alsoKnownAs Agent.BTZ campaign
gptkbp:associatedWith gptkb:Turla_group
gptkbp:connectsTo Russian state-sponsored actors
gptkbp:discoveredBy gptkb:ESET
gptkbp:evolvesFrom gptkb:Agent.BTZ
gptkbp:firstReported 2020
gptkbp:goal espionage
data exfiltration
https://www.w3.org/2000/01/rdf-schema#label ComRAT campaign
gptkbp:notableBattle use of Gmail web interface for C2
gptkbp:target government organizations
military organizations
diplomatic organizations
gptkbp:usesMalware gptkb:Agent.BTZ
gptkb:ComRAT
gptkbp:vectorFor phishing emails
removable media
gptkbp:bfsParent gptkb:Turla_group
gptkbp:bfsLayer 7