Bandook

S0234

Malware.View on attack.mitre.org

About this malware

Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007. It has been used against government, financial, energy, healthcare, education, IT, and legal organizations in the US, South America, Europe, and Southeast Asia. Bandook has been used by Dark Caracal, as well as in a separate campaign referred to as "Operation Manul".

Techniques used26

Procedure examples26

TechniqueProcedure example
T1005
Data from Local System

Bandook can collect local files from the system .

T1016
System Network Configuration Discovery

Bandook has a command to get the public IP address from a system.

T1027.003
Steganography

Bandook has used .PNG images within a zip file to build the executable.

T1041
Exfiltration Over C2 Channel

Bandook can upload files from a victim's machine over the C2 channel.

T1055.012
Process Hollowing

Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload.

T1056.001
Keylogging

Bandook contains keylogging capabilities.

T1059
Command and Scripting Interpreter

Bandook can support commands to execute Java-based payloads.

T1059.001
PowerShell

Bandook has used PowerShell loaders as part of execution.

T1059.003
Windows Command Shell

Bandook is capable of spawning a Windows command shell.

T1059.005
Visual Basic

Bandook has used malicious VBA code against the target system.

T1059.006
Python

Bandook can support commands to execute Python-based payloads.

T1070.004
File Deletion

Bandook has a command to delete a file.

T1083
File and Directory Discovery

Bandook has a command to list files on a system.

T1095
Non-Application Layer Protocol

Bandook has a command built in to use a raw TCP socket.

T1105
Ingress Tool Transfer

Bandook can download files to the system.

View all 26 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. CheckPoint Bandook Nov 2020 Open source
    Check Point. (2020, November 26). Bandook: Signed & Delivered. Retrieved May 31, 2021.
  2. EFF Manul Aug 2016 Open source
    Galperin, E., Et al.. (2016, August). I Got a Letter From the Government the Other Day.... Retrieved April 25, 2018.
  3. Lookout Dark Caracal Jan 2018 Open source
    Blaich, A., et al. (2018, January 18). Dark Caracal: Cyber-espionage at a Global Scale. Retrieved April 11, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.