Bunitu

Malware type
trojan
Family
Malware family
Profile updated
2026-07-07 13:45:23

Context

Bunitu is a trojan that exposes infected computers to be used as a proxy for remote clients. It registers itself at startup by providing its address and open ports. Access to Bunitu proxies is available by using criminal VPN services (e.g.VIP72).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Bunitu_Auto (yara-rule)

Reports & references

  • ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bunitu (report)
  • malwarebreakdown.com — Fobos Malvertising Campaign Delivers Bunitu Proxy Trojan Via Rig Ek (report)
  • zerophagemalware.com — Rig Ek Via Fake Eve Online Website Drops Bunitu (report)
  • blog.malwarebytes.com — Whos Behind Your Proxy Uncovering Bunitus Secrets (report)
  • blog.malwarebytes.com — Revisiting The Bunitu Trojan (report)
  • malware-traffic-analysis.net — Index (report)
  • broadanalysis.com — Rig Exploit Kit Delivers Bunitu Malware (report)

External references