Bunitu
- Malware type
- trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 13:45:23
Context
Bunitu is a trojan that exposes infected computers to be used as a proxy for remote clients. It registers itself at startup by providing its address and open ports. Access to Bunitu proxies is available by using criminal VPN services (e.g.VIP72).
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Bunitu_Auto (yara-rule)
Reports & references
- ptsecurity.com — Paas Or How Hackers Evade Antivirus Software (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bunitu (report)
- malwarebreakdown.com — Fobos Malvertising Campaign Delivers Bunitu Proxy Trojan Via Rig Ek (report)
- zerophagemalware.com — Rig Ek Via Fake Eve Online Website Drops Bunitu (report)
- blog.malwarebytes.com — Whos Behind Your Proxy Uncovering Bunitus Secrets (report)
- blog.malwarebytes.com — Revisiting The Bunitu Trojan (report)
- malware-traffic-analysis.net — Index (report)
- broadanalysis.com — Rig Exploit Kit Delivers Bunitu Malware (report)