BELLHOP

Malware type
backdoor, dropper
Family
Malware family
Profile updated
2026-07-07 12:45:28

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

• BELLHOP is a JavaScript backdoor interpreted using the native Windows Scripting Host(WSH). After performing some basic host information gathering, the BELLHOP dropper downloads a base64-encoded blob of JavaScript to disk and sets up persistence in three ways: • Creating a Run key in the Registry • Creating a RunOnce key in the Registry • Creating a persistent named scheduled task • BELLHOP communicates using HTTP and HTTPS with primarily benign sites such as Google Docs and PasteBin.

Reports & references

  • Mandiant — Fin7 Pursuing An Enigmatic And Evasive Global Criminal Operation (report)
  • cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
  • Mandiant — Cds18 Technical S05 Att&Cking Fin7 (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Bellhop (report)

External references