Brambul

Aliases: SORRYBRUTE

First seen
2017-01-01 00:00:00
Malware type
worm, credential-stealer
Family
Malware family
Profile updated
2026-07-07 12:46:44

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Context

Brambul is a worm that spreads by using a list of hard-coded login credentials to launch a brute-force password attack against an SMB protocol for access to a victim’s networks.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Brambul_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Viewdocument (report)
  • ti.qianxin.com — Cb78386A082F465F259B37Dae5Df4884 (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Brambul (report)
  • metaswan.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 2 (report)
  • us-cert.gov — Ta18 149A (report)
  • swanleesec.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 2 (report)
  • metaswan.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 1 (report)
  • acalvio.com — Lateral Movement Technique Employed By Hidden Cobra (report)
  • secureworks.com — Nickel Academy (report)
  • us-cert.gov — Ar18 149A (report)
  • swanleesec.github.io — Malware Lazarus Group'S Brambul Worm Of The Former Wannacry 1 (report)

External references