BOOKWORM

S1226

Malware.View on attack.mitre.org

About this malware

BOOKWORM is a modular trojan known to be leveraged by Mustang Panda and was first observed utilized in 2015. BOOKWORM was later updated in late 2021 and the fall of 2022 to launch shellcode represented as UUID parameters.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1001.003
Protocol or Service Impersonation

BOOKWORM has modified HTTP POST requests to resemble legitimate communications.

T1027
Obfuscated Files or Information

BOOKWORM has been delivered using self-extracting RAR archives.

T1027.013
Encrypted/Encoded File

BOOKWORM has utilized Base64 encoding to obfuscate its payload.

T1033
System Owner/User Discovery

BOOKWORM has obtained the username from an infected host.

T1036.004
Masquerade Task or Service

BOOKWORM has created services that attempt to resemble legitimate services to include a service named `Microsoft Windows DeviceSync Service`.

T1056.001
Keylogging

BOOKWORM has used its KBLogger.dll module to capture keystrokes and stored them in a folder.

T1070.006
Timestomp

BOOKWORM has modified file timestamps from the export address table (EAT) to make it difficult to discern when the module was created.

T1071.001
Web Protocols

BOOKWORM has communicated with its C2 via HTTP POST requests.

T1106
Native API

BOOKWORM has used various Windows API calls during execution and defense evasion. BOOKWORM has created a buffer on the heap using `HeapCreate` and `HeapAlloc` which allows for copying of shell code and then execution on the heap is initiated through callback function of legitimate API functions such as `EnumChildWindows` or `EnumSystemLanguageGroupsA`.

T1112
Modify Registry

BOOKWORM has modified Registry key values as part of its created service `DeviceSync`.

T1115
Clipboard Data

BOOKWORM has used its KBLogger.dll module to steal data saved to the clipboard.

T1140
Deobfuscate/Decode Files or Information

BOOKWORM has decoded its Base64 encoded payload prior to execution. BOOKWORM has also encrypted files with RC4 and has decrypted its payload prior to execution.

T1543.003
Windows Service

BOOKWORM has created a service named `Microsoft Windows DeviceSync Service` at `HKLM\SYSTEM\CurrentControlSet\Services\DeviceSync\` to trigger execution when the system starts and to maintain persistence.

T1553.002
Code Signing

BOOKWORM has used valid legitimate digital signatures and certificates to evade detection.

T1564.003
Hidden Window

BOOKWORM has created a hidden window when conducting key logging and clipboard theft through its KBLogger.dll module.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Broadcom Open source
    Broadcom Protection Bulletins. (2025, February 20). Bookworm malware linked to Fireant (aka Stately Tarurus) activity observed in Southeast Asia. Retrieved July 21, 2025.
  2. Palo Alto Networks, Unit 42 Open source
    Robert Falcone. (2025, February 20). Stately Taurus Activity in Southeast Asia Links to Bookworm Malware. Retrieved July 21, 2025.
  3. Unit42 Bookworm Nov2015 Open source
    Robert Falcone, Mike Scott, Juan Cortes. (2015, November 10). Bookworm Trojan: A Model of Modular Architecture. Retrieved July 21, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.