Bandook

MITRE ATT&CK: S0234 View on attack.mitre.org

Aliases: Bandok, Bandook

First seen
2007-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
50 (38 malicious)
Last IoC activity
2026-09-01 20:38:53
Profile updated
2026-07-07 12:52:24

Targeted industries: government-and-public-sector financial-services energy-and-utilities healthcare-and-pharmaceutical education-and-nonprofits technology-and-telecommunications professional-services

Targeted regions: country_code:us country_code:br country_code:co country_code:fr country_code:de country_code:es country_code:it country_code:cl country_code:ar

Context

Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007. It has been used against government, financial, energy, healthcare, education, IT, and legal organizations in the US, South America, Europe, and Southeast Asia. Bandook has been used by Dark Caracal, as well as in a separate campaign referred to as "Operation Manul".

Recent IoC activity

38 malicious indicators in Maltiverse are attributed to Bandook (S0234). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname jtoolbox.org 2026-09-03 2
hostname p2020.xyz 2026-09-03 1
hostname bomes.ru 2026-09-03 1
hostname horizongb.com 2026-09-02 1
hostname ercuc.com 2026-09-02 1
hostname r1.panjo.club 2026-09-02 1
hostname vsimperial.com 2026-09-02 1
hostname panjo.club 2026-09-02 1
hostname humut.su 2026-09-02 1
hostname vdscloud.net 2026-09-02 2
hostname cumumberpro.org 2026-09-02 2
hostname ladvsa.club 2026-09-02 1
file sample 2026-07-25_a02822f0ca33b2d221e2933f9f1f02ad_amadey_elex_glassworm_luca-steale... 2026-07-25 1
file sample 2026-07-17_02bd3c728ae921e42e9b5097896a14e1_amadey_elex_glassworm_luca-steale... 2026-07-18 1
file sample 2026-07-17_937f1a063ea78fef8df5f1cacc1f5fa6_amadey_elex_glassworm_luca-steale... 2026-07-17 1
file sample 561cb93118fef1966a3233ae7ffd31017823dd5aaad5dc1b2542e717055c197a.exe 2026-05-20 2
file sample 96e8fb0e9ebec5b0475d53063e9afc83dac0b93f7f1ef1ad36a21bfe56a8df86.exe 2026-05-08 1
hostname poeti-liriki.narod.ru 2026-04-12 1
URL https://poeti-liriki.narod.ru/trainers/102021/a/assassins/acb_latestuplay7tr.zip 2026-04-12 1
URL http://poeti-liriki.narod.ru/trainers/102021/a/assassins/acb_latestuplay7tr.zip 2026-04-12 1

Detection coverage

  • 2 YARA rules
  • 540 Sigma rules

Malware & tools used

  • Audio Capture (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Keylogging (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Steganography (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Screen Capture (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Malicious File (attack-pattern)
  • Native API (attack-pattern)
  • Visual Basic (attack-pattern)
  • Video Capture (attack-pattern)
  • Python (attack-pattern)
  • File Deletion (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Data from Local System (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Bandook (yara-rule)
  • MALPEDIA_Win_Bandook_Auto (yara-rule)

Reports & references

  • info.lookout.com — Lookout Dark Caracal Srr 20180118 Us V.1.0 (report)
  • research.checkpoint.com — Bandook Signed Delivered (report)
  • proofpoint.com — New Threat Actor Uses Spanish Language Lures Distribute Seldom Observed Bandook (report)
  • eff.org — Operation Manul (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bandook (report)
  • ESET — Bandidos At Large Spying Campaign Latin America (report)
  • twitter.com — 796425285197561856 (report)
  • eff.org — Uncle Sow Dark Caracal Latin America (report)
  • fortinet.com — Bandook Persistent Threat That Keeps Evolving (report)
  • eff.org — Dark Caracal You Missed Spot (report)
  • global.ptsecurity.com — The Evolution Of Dark Caracal Tools Analysis Of A Campaign Featuring Poco Rat (report)
  • MITRE ATT&CK — S0234 (report)
  • eff.org — I Got A Letter From The Government (report)

External references