BIOPASS

First seen
2021-04-01 00:00:00
Malware type
rat, screen-capture
Family
Malware family
Profile updated
2026-07-07 13:01:55

Targeted industries: media-and-entertainment

Targeted regions: country_code:cn

Context

BIOPASS RAT is a malware family which targets online gambling companies in China by leveraging a watering hole attack. This Remote Access Trojan (RAT) is unique in that it leverages the Open Broadcaster Software (OBS) framework to monitor the user's screen.

Detection coverage

  • 2 YARA rules

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Biopass_Dropper (yara-rule)
  • DITEKSHEN_INDICATOR_KB_Gobuildid_Biopassdropper (yara-rule)

Reports & references

  • Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Biopass (report)
  • Trend Micro — Biopass Rat New Malware Sniffs Victims Via Live Streaming (report)

External references