Executive Summary
BS2005 is used by the Ke3chang threat actor in long‑running spearphishing campaigns that rely on macro‑enabled Office attachments or malicious links. The malware serves as a delivery vector for subsequent payloads, enabling credential theft and system compromise. Immediate detection requires email filtering, monitoring of outbound traffic, and disabling of macros.
Enhanced Description
BS2005 is a Windows‑based malware that has been documented as part of Ke3chang’s spearphishing operations since at least 2011. The campaign began with carefully crafted phishing emails containing malicious attachments or links designed to entice users into executing embedded malware. Once the user engages with the malicious component, BS2005 typically triggers a secondary download stage, fetching additional payloads from an attacker‑controlled command–and–control infrastructure. While detailed technical documentation is scarce, analysts infer that BS2005 leverages standard Office macro exploitation and possibly executable dropper techniques common to Ke3chang campaigns. The malware’s objectives appear centered around credential harvesting, system reconnaissance, and establishing a foothold for subsequent lateral movement or data exfiltration. Impact assessments highlight that the threat can disrupt affected hosts with command‑line capabilities and potentially exfiltrate sensitive information if left unchecked. Defenses against BS2005 primarily focus on email filtering, macro disabling, and monitoring outbound connections to known malicious destinations. In environments where phishing is a persistent risk, it is advisable to enforce strict attachment policies and deploy endpoint protection capable of identifying suspicious script execution.
Key Capabilities
Recommended Actions
Confidence Assessment
The assessment is based on limited publicly available information from a Mandiant report. Key behaviors are inferred from typical Ke3chang techniques, but specific low‑level capabilities of BS2005 remain unverified due to the lack of open-source artifacts or technical samples. Confidence in high‑level threat model is moderate; gaps persist around persistence mechanisms and detailed command sets.
BS2005 is malware that was used by Ke3chang in spearphishing campaigns since at least 2011. (Citation: Mandiant Operation Ke3chang November 2014)