BOOKWORM

MITRE ATT&CK: S1226 View on attack.mitre.org

Aliases: BOOKWORM

First seen
2015-01-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:19:15

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

BOOKWORM is a modular trojan known to be leveraged by Mustang Panda and was first observed utilized in 2015. BOOKWORM was later updated in late 2021 and the fall of 2022 to launch shellcode represented as UUID parameters.

Detection coverage

  • 395 Sigma rules

Malware & tools used

  • System Owner/User Discovery (attack-pattern)
  • Code Signing (attack-pattern)
  • Web Protocols (attack-pattern)
  • Modify Registry (attack-pattern)
  • Windows Service (attack-pattern)
  • Hidden Window (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • DLL (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Keylogging (attack-pattern)
  • Native API (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Timestomp (attack-pattern)
  • Protocol or Service Impersonation (attack-pattern)
  • Clipboard Data (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Bookworm Trojan A Model Of Modular Architecture (report)
  • Palo Alto Unit 42 — Stately Taurus Uses Bookworm Malware (report)
  • Broadcom/Symantec — Bookworm Malware Linked To Fireant Aka Stately Tarurus Activity Observed In Southeast Asia (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bookworm (report)
  • MITRE ATT&CK — S1226 (report)

External references