BookCodes RAT

Aliases: BookCodesTea

Malware type
rat
Family
Malware family
Profile updated
2026-07-07 12:46:53

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr

Context

BookCodesRAT is a remote access trojan that uses HTTP(S) for communication. It supports around 25 commands that include operations on the victim’s filesystem, basic process management and the download and execution of additional tools from the attacker’s arsenal. They are indexed by 32-bit integers, starting with the value 0x97853646. BookCodesRAT uses mostly compromised South Korean web servers for the C&C traffic and is usually deployed against South Korean targets.

Reports & references

  • ESET — Lazarus Supply Chain Attack South Korea (report)
  • vblocalhost.com — Vb2021 Park (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bookcodesrat (report)
  • boho.or.kr — Filedownload.Do (report)
  • Kaspersky — 99906 (report)
  • boho.or.kr — Filedownload.Do (report)
  • vblocalhost.com — Vb2021 Lee Etal (report)

External references