Buhtrap

Aliases: Ratopak

Malware type
trojan, credential-stealer, backdoor
Family
Malware family
Profile updated
2026-07-07 12:45:50

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:ru country_code:ua

Context

Buhtrap is a sophisticated malware family primarily targeting financial institutions and government organizations in Russia and Ukraine. It functions as a credential stealer and backdoor, facilitating unauthorized access and financial theft.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Buhtrap_Maldocx (yara-rule)
  • MALPEDIA_Win_Buhtrap_Auto (yara-rule)

Reports & references

  • group-ib.com — Gib Buhtrap Report (report)
  • Broadcom/Symantec — Viewdocument (report)
  • ESET — Operation Buhtrap (report)
  • ptsecurity.com — Operation Ta505 Part3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Buhtrap (report)
  • scythe.io — Threatthursday Buhtrap (report)
  • Broadcom/Symantec — Russian Bank Employees Received Fake Job Offers Targeted Email Attack (report)
  • blog.dcso.de — Pegasus Buhtrap Analysis Of The Malware Stage Based On The Leaked Source Code (report)
  • ESET — Buhtrap Backdoor Ransomware Advertising Platform (report)
  • malware-research.org — Carbanak Source Code Leaked (report)
  • ESET — Buhtrap Zero Day Espionage Campaigns (report)
  • dcso.de — Pegasus Buhtrap Analysis Of The Malware Stage Based On The Leaked Source Code (report)

External references