BUFFETLINE

First seen
2020-10-01 00:00:00
Malware type
rat
Profile updated
2026-07-07 14:45:22

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:us country_code:gb

Context

BUFFETLINE is a remote access tool (RAT) used primarily in cyber espionage campaigns targeting government and financial sectors, particularly in the United States and the United Kingdom. Its capabilities include network reconnaissance and data exfiltration.

Reports & references

  • labs.sentinelone.com — Dprk Hidden Cobra Update North Korean Malicious Cyber Activity (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Buffetline (report)
  • us-cert.gov — Ar20 045F (report)

External references