BHunt

Malware type
credential-stealer, trojan
Family
Malware family
Profile updated
2026-07-07 14:49:06

Targeted industries: financial-services technology-and-telecommunications

Context

BHunt collects the crypto wallets of its victims. The malware consists of several functions/modules, e.g. a reporting module that reports the presence of crypto wallets on the target computers to the C2 server. It searches for many different cryptocurrencies (e.g. Atomic, Bitcoin, Electrum, Ethereum, Exodus, Jaxx and Litecoin). The Blackjack module is used to steal wallets, Sweet_Bonanza steals victims' browser passwords. There are also modules like the Golden7 or the Chaos_crew module.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Win_Bhunt (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Bhunt (report)
  • bleepingcomputer.com — New Bhunt Malware Targets Your Crypto Wallets And Passwords (report)
  • blogs.blackberry.com — Threat Thursday Bhunt Scavenger (report)
  • bitdefender.com — Bitdefender Pr Whitepaper Cyberwallet Creat5874 En En (report)

External references