Skip to content

Bandook

Bandook is a Windows remote-access trojan (RAT) used for espionage and remote control of compromised systems.

Profile source: Mallory opens in a new tab

Bandook

Family profile

Bandook is a Windows remote-access trojan (RAT) used for espionage and remote control of compromised systems. It has been associated with the Lebanon-linked Dark Caracal threat actor, including operations in which it was deployed alongside the GoCaracal framework rather than replaced by it. Bandook supports desktop screenshot capture and upload, keylogging, local-file collection and upload over its command-and-control channel, file deletion, and public IP-address discovery. Documented execution and evasion behavior includes PowerShell-based loaders, malicious VBA macro code delivered through lure documents that prompt users to enable macros, and process hollowing in which a legitimate browser process is started and replaced with the Bandook payload. An updated 2026 variant used randomized command identifiers and obfuscated plugin export names, and included browser credential collection capability.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Process Injection
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 28, 2026
Last activity
Aug 28, 2026
Feed role
C2
Host form
0 IP / 7 hostnames

Leading locations

  • US1

Leading providers

  • Hostinger International Limited1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Reported operators

Threat actors

4 named in public reporting
Dark Caracal

Bandook was delivered in the same intrusion, showing that the newer GoCaracal framework is adding to, rather than immediately replacing, Dark Caracal's existing toolkit.

Darkling APT

The group is known to leverage Bandook-based backdoors in their attacks.

Caliente Bandits

The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.

TA2721

The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.

MITRE ATT&CK

Bandook in ATT&CK

56 distinct techniques

Techniques

56 techniques
T1566.002 Spearphishing Link T1566.001 Spearphishing Attachment T1566 Phishing T1105 Ingress Tool Transfer T1204.002 Malicious File T1027 Obfuscated Files or Information T1195.002 Compromise Software Supply Chain T1555.003 Credentials from Web Browsers T1059.001 PowerShell T1113 Screen Capture T1120 Peripheral Device Discovery T1056.001 Keylogging T1055.012 Process Hollowing T1070.004 File Deletion T1082 System Information Discovery T1005 Data from Local System T1016 System Network Configuration Discovery T1204 User Execution T1059.005 Visual Basic T1083 File and Directory Discovery T1140 Deobfuscate/Decode Files or Information T1041 Exfiltration Over C2 Channel T1106 Native API T1059.003 Windows Command Shell T1573 Encrypted Channel T1547.001 Registry Run Keys / Startup Folder T1027.013 Encrypted/Encoded File T1112 Modify Registry T1036 Masquerading T1123 Audio Capture T1055 Process Injection T1059.006 Python T1497 Virtualization/Sandbox Evasion T1547.004 Winlogon Helper DLL T1560 Archive Collected Data T1539 Steal Web Session Cookie T1125 Video Capture T1071 Application Layer Protocol T1059 Command and Scripting Interpreter T1056 Input Capture T1057 Process Discovery T1573.001 Symmetric Cryptography T1204.001 Malicious Link T1025 Data from Removable Media T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1219 Remote Access Tools T1555 Credentials from Password Stores T1001 Data Obfuscation T1071.001 Web Protocols T1059.007 JavaScript T1132 Data Encoding T1553.002 Code Signing T1027.002 Software Packing T1095 Non-Application Layer Protocol T1027.003 Steganography T1680 Local Storage Discovery

Reporting

Research mentioning Bandook

Aug 26
Malware News

Dark Caracal Reloaded: New Malware, Same Hunting Grounds - Malware News - Malware Analysis, News and Indicators

Arctic Wolf Labs investigated a targeted June 2026 intrusion against a communications organization in Venezuela and assessed with medium confidence that the activity was linked to the Dark Caracal threat group. The operation continues the actor's established focus on Latin America, using newly identified malware while pursuing targets in its familiar regional hunting grounds. Researchers linked 249 malware samples to two operational build profiles, indicating a structured and evolving tooling ecosystem. The campaign also used a resilient command-and-control architecture built on Ethereum, complicating disruption and enabling the operators to maintain infrastructure despite conventional takedown efforts.

Aug 26
Arctic Wolf

Dark Caracal Reloaded: New Malware, Same Hunting Grounds - Arctic Wolf

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.