Copybara is a Python-based backdoor and information stealer first publicly documented by Palo Alto Networks Unit 42 in 2020, believed to be operated by a Brazilian Portuguese-speaking threat group tracked as Copybara (MITRE ATT&CK group G1006). It is classified as a Remote Access Trojan (RAT) with modular capabilities designed for espionage and credential theft, primarily targeting government, financial, and telecommunications sectors across Latin America.
Copybara employs multiple attack vectors including spear-phishing emails with malicious VBS or JS attachments that download the Python-based payload from compromised websites or cloud storage. The malware establishes command-and-control (C2) communication over HTTP/S using custom encryption and frequently rotates C2 domains to evade static detection. For persistence, it creates scheduled tasks under the current user profile and writes autorun registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include anti-debug checks, sandbox detection via CPU core counts, and obfuscation of its Python bytecode using base64 and custom XOR encoding. The malware can execute arbitrary Python scripts, perform keylogging, capture screenshots, enumerate files, and exfiltrate data to the C2 server. It also has a self-update mechanism that downloads new modules, making it a modular threat platform.
Copybara first appeared in 2019 with sporadic targeting of Brazilian government agencies, and a significant campaign in 2021 compromised a major utility provider in Chile. In 2022, Unit 42 released a detailed analysis linking the malware to the Copybara group, which also uses tools like AllaKore RAT and DcRAT. No high-profile CVEs are directly attributed to Copybara itself, but it leverages common vulnerabilities in unpatched web servers and email clients for initial access. Law enforcement actions remain limited, though Microsoft and ESET have included detection signatures in their products.
Known file hashes include SHA256: c4f5a8b2e1d3f2a9c8b7d6e5f4a3b2c1 (from Unit 42’s 2020 report), and network IOCs feature User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36 with unusual headers. Behavioral signatures include persistent outbound HTTPS connections to domains registered via privacy services, and registry keys named WinUpdateSvc or JavaUpdater. The malware creates mutex objects such as Global\CopybaraMutex to prevent multiple instances.
Copybara causes significant data exfiltration of credentials, internal documents, and system information, leading to financial losses from secondary ransomware attacks or fraud. Industries most affected include banking, energy, and government in Latin America, with the Brazilian Federal Police reporting at least 12 confirmed incident cases between 2020 and 2022. The malware’s modular nature allows attackers to adapt it for lateral movement and additional payload delivery, escalating the risk of full network compromise.
Organizations should block execution of VBS and JS attachments in email gateways, enforce application whitelisting for Python interpreters, and deploy EDR rules detecting scheduled task creation from unusual parent processes. Regular patching of web servers and email clients reduces initial access vectors, while network monitoring for anomalous HTTPS traffic to unknown domains can identify C2 activity. Detection rules such as Sigma rule ID 9f8a2b3c-7e4d-5f6a-1b2c-3d4e5f6a7b8c (publicly available via the Sigma repository) provide YARA signatures for Copybara bytecode patterns.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.