Malware.View on attack.mitre.org
Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007. It has been used against government, financial, energy, healthcare, education, IT, and legal organizations in the US, South America, Europe, and Southeast Asia. Bandook has been used by Dark Caracal, as well as in a separate campaign referred to as "Operation Manul".
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
Bandook can collect local files from the system . |
| T1016 System Network Configuration Discovery |
Bandook has a command to get the public IP address from a system. |
| T1027.003 Steganography |
Bandook has used .PNG images within a zip file to build the executable. |
| T1041 Exfiltration Over C2 Channel |
Bandook can upload files from a victim's machine over the C2 channel. |
| T1055.012 Process Hollowing |
Bandook has been launched by starting iexplore.exe and replacing it with Bandook's payload. |
| T1056.001 Keylogging |
Bandook contains keylogging capabilities. |
| T1059 Command and Scripting Interpreter |
Bandook can support commands to execute Java-based payloads. |
| T1059.001 PowerShell |
Bandook has used PowerShell loaders as part of execution. |
| T1059.003 Windows Command Shell |
Bandook is capable of spawning a Windows command shell. |
| T1059.005 Visual Basic |
Bandook has used malicious VBA code against the target system. |
| T1059.006 Python |
Bandook can support commands to execute Python-based payloads. |
| T1070.004 File Deletion |
Bandook has a command to delete a file. |
| T1083 File and Directory Discovery |
Bandook has a command to list files on a system. |
| T1095 Non-Application Layer Protocol |
Bandook has a command built in to use a raw TCP socket. |
| T1105 Ingress Tool Transfer |
Bandook can download files to the system. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.