Bandook
MITRE ATT&CK: S0234 View on attack.mitre.org
Aliases: Bandok, Bandook
- First seen
- 2007-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 50 (38 malicious)
- Last IoC activity
- 2026-09-01 20:38:53
- Profile updated
- 2026-07-07 12:52:24
Targeted industries: government-and-public-sector financial-services energy-and-utilities healthcare-and-pharmaceutical education-and-nonprofits technology-and-telecommunications professional-services
Targeted regions: country_code:us country_code:br country_code:co country_code:fr country_code:de country_code:es country_code:it country_code:cl country_code:ar
Context
Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007. It has been used against government, financial, energy, healthcare, education, IT, and legal organizations in the US, South America, Europe, and Southeast Asia. Bandook has been used by Dark Caracal, as well as in a separate campaign referred to as "Operation Manul".
Recent IoC activity
38 malicious indicators in Maltiverse are attributed to Bandook (S0234). The 20 most recently updated:
Detection coverage
- 2 YARA rules
- 540 Sigma rules
Malware & tools used
- Audio Capture (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Windows Command Shell (attack-pattern)
- Keylogging (attack-pattern)
- Process Hollowing (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Steganography (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Screen Capture (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Malicious File (attack-pattern)
- Native API (attack-pattern)
- Visual Basic (attack-pattern)
- Video Capture (attack-pattern)
- Python (attack-pattern)
- File Deletion (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Data from Local System (attack-pattern)
Used by threat actors
- Dark Caracal (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Bandook (yara-rule)
- MALPEDIA_Win_Bandook_Auto (yara-rule)
Reports & references
- info.lookout.com — Lookout Dark Caracal Srr 20180118 Us V.1.0 (report)
- research.checkpoint.com — Bandook Signed Delivered (report)
- proofpoint.com — New Threat Actor Uses Spanish Language Lures Distribute Seldom Observed Bandook (report)
- eff.org — Operation Manul (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bandook (report)
- ESET — Bandidos At Large Spying Campaign Latin America (report)
- twitter.com — 796425285197561856 (report)
- eff.org — Uncle Sow Dark Caracal Latin America (report)
- fortinet.com — Bandook Persistent Threat That Keeps Evolving (report)
- eff.org — Dark Caracal You Missed Spot (report)
- global.ptsecurity.com — The Evolution Of Dark Caracal Tools Analysis Of A Campaign Featuring Poco Rat (report)
- MITRE ATT&CK — S0234 (report)
- eff.org — I Got A Letter From The Government (report)