| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1071 | .004 | Application Layer Protocol: DNS | |
| Enterprise | T1005 | Data from Local System | SombRAT has collected data and files from a compromised host.[1][3] | |
| Enterprise | T1074 | .001 | Data Staged: Local Data Staging | SombRAT can store harvested data in a custom database under the %TEMP% directory.[1] | 
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | SombRAT can run  | |
| Enterprise | T1568 | .002 | Dynamic Resolution: Domain Generation Algorithms | SombRAT can use a custom DGA to generate a subdomain for C2.[1] | 
| Enterprise | T1573 | .002 | Encrypted Channel: Asymmetric Cryptography | |
| Enterprise | T1083 | File and Directory Discovery | SombRAT can execute  | |
| Enterprise | T1564 | .010 | Hide Artifacts: Process Argument Spoofing | SombRAT has the ability to modify its process memory to hide process command-line arguments.[2] | 
| Enterprise | T1070 | .004 | Indicator Removal on Host: File Deletion | SombRAT has the ability to run  | 
| Enterprise | T1105 | Ingress Tool Transfer | SombRAT has the ability to download and execute additional payloads.[1][2][3] | |
| Enterprise | T1036 | Masquerading | SombRAT can use a legitimate process name to hide itself.[3] | |
| Enterprise | T1106 | Native API | SombRAT has the ability to respawn itself using  | |
| Enterprise | T1095 | Non-Application Layer Protocol | SombRAT has the ability to use TCP sockets to send data and ICMP to ping the C2 server.[1][2] | |
| Enterprise | T1027 | Obfuscated Files or Information | SombRAT can encrypt strings with XOR-based routines and use a custom AES storage format for plugins, configuration, C2 domains, and harvested data.[1][2][3] | |
| Enterprise | T1057 | Process Discovery | SombRAT can use the  | |
| Enterprise | T1055 | .001 | Process Injection: Dynamic-link Library Injection | SombRAT can execute  | 
| Enterprise | T1090 | Proxy | SombRAT has the ability to use an embedded SOCKS proxy in C2 communications.[3] | |
| Enterprise | T1082 | System Information Discovery | SombRAT can execute  | |
| Enterprise | T1033 | System Owner/User Discovery | SombRAT can execute  | |
| Enterprise | T1007 | System Service Discovery | ||
| Enterprise | T1124 | System Time Discovery | SombRAT can execute  | |
| ID | Name | References | 
|---|---|---|
| G0132 | CostaRicto |