BetaBot
Aliases: Neurevt
- First seen
- 2012-12-01 00:00:00
- Malware type
- credential-stealer, trojan, spyware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:51
- Profile updated
- 2026-07-07 13:45:01
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Context
Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012. The malware began as a banking Trojan and is now packed with features that allow its operators to practically take over a victim’s machine and steal sensitive information.
Detection coverage
- 2 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Betabot (yara-rule)
- MALPEDIA_Win_Betabot_Auto (yara-rule)
Related threat objects
- BetaBot (infrastructure)
Reports & references
- medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
- news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
- news.sophos.com — Raticate (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Betabot (report)
- malwaredigger.com — How To Extract Betabot Config Info (report)
- krabsonsecurity.com — Betabot In The Rearview Mirror (report)
- ccn-cert.cni.es — 6087 Betabot Y Fleercivet Dos Nuevos Informes De Codigo Danino Del Ccn Cert (report)
- Kaspersky — 101638 (report)
- resources.infosecinstitute.com — Beta Bot Analysis Part 1 (report)
- sophos.com — Betabot (report)
- medium.com — Betabot Still Alive With Multi Stage Packing Fbe8Ef211D39 (report)
- xylibox.com — Betabot Retrospective (report)
- cybereason.com — Betabot Banking Trojan Neurevt (report)