These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
Betabot
BetaBot, also known as Neurevt, is a Windows malware family that emerged in late 2012 as a banking Trojan and later evolved into a multifunction infostealer and bot.
Betabot
Family profile
BetaBot, also known as Neurevt, is a Windows malware family that emerged in late 2012 as a banking Trojan and later evolved into a multifunction infostealer and bot. It is designed to steal sensitive information from infected systems and support broader post-compromise activity under operator control. Documented capabilities include browser form grabbing, theft of credentials from FTP and mail clients, arbitrary command execution, malware download, DDoS functionality, USB propagation, and persistence. Some versions also incorporated a cryptocurrency mining component. Administrative-panel features observed across versions indicate support for bot management, tasking, updates, file retrieval, SOCKS proxying, URL visitation, and collection of form-grabber logs.
Observed intrusion chains show BetaBot being delivered through phishing campaigns using weaponized Microsoft Office documents, including RTF-based lures exploiting CVE-2017-11882 in the Equation Editor component. It has also been delivered through exploit-kit activity, including Sweet Orange campaigns exploiting CVE-2014-6332, and through malware distribution operations such as RATicate, which used malicious spam and NSIS-based loaders to deploy multiple commodity stealers and RATs including BetaBot. In these chains, BetaBot has been unpacked by droppers or loaders and then injected into running Windows processes for execution.
On infected hosts, BetaBot has been observed unpacking its payload and injecting into child or legitimate processes, commonly Explorer.exe, as part of execution and evasion. It establishes persistence through autorun mechanisms and in some cases scheduled tasks. It also modifies permissions on persistence artifacts and uses API hooking to conceal persistence from common administrative and monitoring tools. Anti-analysis and self-protection features include anti-debugging, anti-virtualization and anti-sandbox checks, detection of numerous security products, interference with security tooling, DNS blocking of security vendors, and a BotKiller capability intended to identify or suppress competing malware.
BetaBot has appeared in criminal malware ecosystems both as a primary payload and as a secondary task distributed by other malware. It has been associated with broad financially motivated activity rather than a single exclusive operator, and has been seen alongside families such as LokiBot, Formbook, AgentTesla, NetWire, Andromeda, and other commodity crimeware. Targeting has included enterprise environments and organizations in multiple regions, with phishing lures often themed around business transactions. The family is best characterized as a mature Windows infostealer with banking-Trojan heritage, modular operator tasking, and strong defense-evasion features.
Capabilities
- Credential Theft
- Ddos
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Spoofing
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Betabot
2 CVEsMITRE ATT&CK