Buhtrap
Aliases: Ratopak
- Malware type
- trojan, credential-stealer, backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 12:45:50
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:ru country_code:ua
Context
Buhtrap is a sophisticated malware family primarily targeting financial institutions and government organizations in Russia and Ukraine. It functions as a credential stealer and backdoor, facilitating unauthorized access and financial theft.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Apt_Buhtrap_Maldocx (yara-rule)
- MALPEDIA_Win_Buhtrap_Auto (yara-rule)
Reports & references
- group-ib.com — Gib Buhtrap Report (report)
- Broadcom/Symantec — Viewdocument (report)
- ESET — Operation Buhtrap (report)
- ptsecurity.com — Operation Ta505 Part3 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Buhtrap (report)
- scythe.io — Threatthursday Buhtrap (report)
- Broadcom/Symantec — Russian Bank Employees Received Fake Job Offers Targeted Email Attack (report)
- blog.dcso.de — Pegasus Buhtrap Analysis Of The Malware Stage Based On The Leaked Source Code (report)
- ESET — Buhtrap Backdoor Ransomware Advertising Platform (report)
- malware-research.org — Carbanak Source Code Leaked (report)
- ESET — Buhtrap Zero Day Espionage Campaigns (report)
- dcso.de — Pegasus Buhtrap Analysis Of The Malware Stage Based On The Leaked Source Code (report)