BookCodes RAT
Aliases: BookCodesTea
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:46:53
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:kr
Context
BookCodesRAT is a remote access trojan that uses HTTP(S) for communication. It supports around 25 commands that include operations on the victim’s filesystem, basic process management and the download and execution of additional tools from the attacker’s arsenal. They are indexed by 32-bit integers, starting with the value 0x97853646. BookCodesRAT uses mostly compromised South Korean web servers for the C&C traffic and is usually deployed against South Korean targets.
Reports & references
- ESET — Lazarus Supply Chain Attack South Korea (report)
- vblocalhost.com — Vb2021 Park (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bookcodesrat (report)
- boho.or.kr — Filedownload.Do (report)
- Kaspersky — 99906 (report)
- boho.or.kr — Filedownload.Do (report)
- vblocalhost.com — Vb2021 Lee Etal (report)