BetaBot

Aliases: Neurevt

First seen
2012-12-01 00:00:00
Malware type
credential-stealer, trojan, spyware
Family
Malware family
Last IoC activity
2026-07-22 00:36:51
Profile updated
2026-07-07 13:45:01

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012. The malware began as a banking Trojan and is now packed with features that allow its operators to practically take over a victim’s machine and steal sensitive information.

Detection coverage

  • 2 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Betabot (yara-rule)
  • MALPEDIA_Win_Betabot_Auto (yara-rule)

Related threat objects

  • BetaBot (infrastructure)

Reports & references

  • medium.com — Inside View Of Brazzzersff Infrastructure 89B9188Fd145 (report)
  • news.sophos.com — Raticate Rats As Service With Commercial Crypter (report)
  • news.sophos.com — Raticate (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Betabot (report)
  • malwaredigger.com — How To Extract Betabot Config Info (report)
  • krabsonsecurity.com — Betabot In The Rearview Mirror (report)
  • ccn-cert.cni.es — 6087 Betabot Y Fleercivet Dos Nuevos Informes De Codigo Danino Del Ccn Cert (report)
  • Kaspersky — 101638 (report)
  • resources.infosecinstitute.com — Beta Bot Analysis Part 1 (report)
  • sophos.com — Betabot (report)
  • medium.com — Betabot Still Alive With Multi Stage Packing Fbe8Ef211D39 (report)
  • xylibox.com — Betabot Retrospective (report)
  • cybereason.com — Betabot Banking Trojan Neurevt (report)

External references