Bisonal
MITRE ATT&CK: S0268 View on attack.mitre.org
Aliases: Bisonal
- First seen
- 2010-12-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2024-11-29 20:27:56
- Profile updated
- 2026-07-07 13:19:00
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ru country_code:kr country_code:jp
Context
Bisonal is a remote access tool (RAT) that has been used by Tonto Team against public and private sector organizations in Russia, South Korea, and Japan since at least December 2010.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Bisonal (S0268). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | hairouni.serveblog.net | 2024-11-29 | 1 |
Detection coverage
- 592 Sigma rules
Malware & tools used
- Native API (attack-pattern)
- File Deletion (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Process Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Virtualization/Sandbox Evasion (attack-pattern)
- Windows Service (attack-pattern)
- Add-ins (attack-pattern)
- Visual Basic (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Data from Local System (attack-pattern)
- Time Based Checks (attack-pattern)
- Web Protocols (attack-pattern)
- Modify Registry (attack-pattern)
- Rundll32 (attack-pattern)
- Malicious File (attack-pattern)
- Binary Padding (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Standard Encoding (attack-pattern)
- Query Registry (attack-pattern)
- Software Packing (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
Used by threat actors
- Tonto Team (threat-actor)
Reports & references
- Cisco Talos — Bisonal 10 Years Of Play (report)
- researchcenter.paloaltonetworks.com — Unit42 Bisonal Malware Used Attacks Russia South Korea (report)
- MITRE ATT&CK — S0268 (report)