Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Bandook

Bandook

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

Bandook is a legacy commercial RAT capable of remote desktop control and extensive credential theft, targeting high‑profile sectors worldwide. First seen over a decade ago, it remains actively used by groups such as Dark Caracal in targeted campaigns like "Operation Manul." The malware’s persistence and data exfiltration capabilities pose significant risk to government and critical infrastructure assets.

Enhanced Description

Bandook is a commercial remote‑access trojan (RAT) that has been available since at least 2007. The code base is written in Delphi alongside a C++ component, allowing the malware to blend both managed and native Windows APIs for persistence and stealth. The Trojan provides attackers with comprehensive control over compromised hosts, including full remote desktop emulation, system command execution, file exfiltration, and credential theft. Operators often use Bandook to conduct large‑scale campaigns against high‑value targets in the government, financial, energy, healthcare, education, IT, and legal sectors across the United States, South America, Europe, and Southeast Asia. Bandook has been linked to multiple APT groups, notably Dark Caracal, and was used in an operation referred to as "Operation Manul". Its deployment frequently involves spear‑phishing or supply‑chain vectors that deliver the bundled Delphi/C++ executable. Although specific configuration details vary by campaign, the malware consistently demonstrates advanced persistence mechanisms, lateral movement capabilities, and a strong focus on exfiltrating sensitive data from diverse industrial control environments.

Key Capabilities

  • Remote desktop control via virtual display
  • Command execution using PowerShell or command line interpreters
  • Credential harvesting from browser & system caches
  • File upload/download for exfiltration
  • Persistence through registry autorun or scheduled tasks
  • Lateral movement across Windows workstations with SMB and RDP

ATT&CK Techniques

T1059
T1076
T1543
T1014

Recommended Actions

  • Deploy behavior‑based endpoint detection to flag anomalous remote desktop sessions and background services named after Bandook components
  • Block known malicious IPs, domains, and file hashes associated with Bandook campaigns via firewall/UTM rules
  • Update antivirus signatures covering Delphi/C++ compiled stubs of Bandook
  • Implement AppLocker or similar allowlisting techniques for executable paths typical of RAT installations
  • Enforce least privilege policies and monitor for unauthorized creation of scheduled tasks
  • Conduct regular security awareness training focusing on spear‑phishing scenarios linked to Bandook delivery

Suggested Tags

RAT
Delphi-C++ Hybrid
Targeted APT Campaigns
Spear‑phishing Delivery
Industrial Control System Threat
Government & Critical Infrastructure

Confidence Assessment

Confidence in the high‑level operational profile of Bandook is moderate; multiple independent reports (EFF, Lookout, CheckPoint) confirm its use by targeted campaigns. However, detailed technical data such as exact persistence vectors, C2 protocol specifics, and embedded obfuscation techniques are incomplete, limiting granular detection rule development.

Description

Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007. It has been used against government, financial, energy, healthcare, education, IT, and legal organizations in the US, South America, Europe, and Southeast Asia. Bandook has been used by Dark Caracal, as well as in a separate campaign referred to as "Operation Manul".(Citation: EFF Manul Aug 2016)(Citation: Lookout Dark Caracal Jan 2018)(Citation: CheckPoint Bandook Nov 2020)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.