CometBot
Malware⚠️ Overview
CometBot is a Java‑based remote access trojan (RAT) first documented by Fortinet’s FortiGuard Labs in November 2022 and attributed to the TA473 threat group (tracked as Silver Fox). It functions as a modular backdoor primarily used for credential theft, keylogging, and data exfiltration against financial sector targets.
🔧 Technical Capabilities
CometBot propagates via phishing emails containing weaponized Excel attachments that execute VBA macros to drop the primary payload. It communicates with command‑and‑control (C2) infrastructure over HTTP POST requests using AES‑256 encryption for beaconing and payload delivery (MITRE ATT&CK T1071.001). Persistence is achieved through scheduled tasks and registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRunCometUpdater). Evasion techniques include process hollowing (T1055.012), API unhooking to bypass endpoint detection, and embedding malicious code within legitimate Java runtime processes. The RAT can enumerate browser credentials from Chrome, Firefox, and Edge, capture screenshots, log keystrokes, and download additional modules (e.g., a VNC plugin for remote desktop hijacking). C2 infrastructure often leverages compromised WordPress sites and cloud‑based hosting providers to blend with legitimate traffic.
📜 History & Notable Incidents
First observed in Q4 2022, CometBot primarily targeted European banking institutions in campaigns that escalated through mid‑2023. No high‑profile victims have been publicly named, but Fortinet reported campaigns against small‑to‑medium financial firms in Germany and Poland. No critical CVEs are directly exploited; instead, the malware relies on social engineering and macro‑enabled Office documents. Law enforcement actions have not been documented, though the group’s TTPs overlap with the broader Silver Fox cluster monitored by the FBI.
🔍 Detection Indicators
Known SHA‑256 hashes include 5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5 (archived on VirusTotal under the “CometBot” tag). Network indicators include HTTP POST requests to /gate.php or /api/beacon with a unique User‑Agent string Mozilla/5.0 (compatible; CometBot/1.0; Win64). Persistence writes a scheduled task named CometUpdateTask and creates a mutex GlobalCometMutex to prevent multiple instances.
☠️ Risk & Impact
CometBot can exfiltrate sensitive documents, saved passwords, and bank login credentials, leading to direct financial theft and account takeover. The primary impact is credential theft and lateral movement within financial networks, with potential for ransomware deployment as a secondary payload. Affected sectors are predominantly banking, e‑commerce, and payment processing firms in Europe and North America.
🛡️ Mitigation
Disable macro execution in Office via Group Policy, deploy endpoint detection rules for process injection (T1055.012) and scheduled task creation, and block outbound HTTP POST traffic to unknown domains containing /gate.php. Fortinet’s AV signatures (W32/CometBot!tr) and Zeek scripts detecting the User‑Agent string are effective; keep Java runtime updated and apply URL filtering against known C2 domains published by FortiGuard.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.