Last seven days
- First activity
- Aug 28, 2026
- Last activity
- Aug 28, 2026
- Feed role
- C2
- Host form
- 0 IP / 7 hostnames
Bandook is a Windows remote-access trojan (RAT) used for espionage and remote control of compromised systems.
Profile source: Mallory opens in a new tabBandook
Bandook is a Windows remote-access trojan (RAT) used for espionage and remote control of compromised systems. It has been associated with the Lebanon-linked Dark Caracal threat actor, including operations in which it was deployed alongside the GoCaracal framework rather than replaced by it. Bandook supports desktop screenshot capture and upload, keylogging, local-file collection and upload over its command-and-control channel, file deletion, and public IP-address discovery. Documented execution and evasion behavior includes PowerShell-based loaders, malicious VBA macro code delivered through lure documents that prompt users to enable macros, and process hollowing in which a legitimate browser process is started and replaced with the Bandook payload. An updated 2026 variant used randomized command identifiers and obfuscated plugin export names, and included browser credential collection capability.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Bandook was delivered in the same intrusion, showing that the newer GoCaracal framework is adding to, rather than immediately replacing, Dark Caracal's existing toolkit.
The group is known to leverage Bandook-based backdoors in their attacks.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
MITRE ATT&CK
Reporting
Arctic Wolf Labs investigated a targeted June 2026 intrusion against a communications organization in Venezuela and assessed with medium confidence that the activity was linked to the Dark Caracal threat group. The operation continues the actor's established focus on Latin America, using newly identified malware while pursuing targets in its familiar regional hunting grounds. Researchers linked 249 malware samples to two operational build profiles, indicating a structured and evolving tooling ecosystem. The campaign also used a resilient command-and-control architecture built on Ethereum, complicating disruption and enabling the operators to maintain infrastructure despite conventional takedown efforts.
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.