Executive Summary
Bandook is a legacy commercial RAT capable of remote desktop control and extensive credential theft, targeting high‑profile sectors worldwide. First seen over a decade ago, it remains actively used by groups such as Dark Caracal in targeted campaigns like "Operation Manul." The malware’s persistence and data exfiltration capabilities pose significant risk to government and critical infrastructure assets.
Enhanced Description
Bandook is a commercial remote‑access trojan (RAT) that has been available since at least 2007. The code base is written in Delphi alongside a C++ component, allowing the malware to blend both managed and native Windows APIs for persistence and stealth. The Trojan provides attackers with comprehensive control over compromised hosts, including full remote desktop emulation, system command execution, file exfiltration, and credential theft. Operators often use Bandook to conduct large‑scale campaigns against high‑value targets in the government, financial, energy, healthcare, education, IT, and legal sectors across the United States, South America, Europe, and Southeast Asia. Bandook has been linked to multiple APT groups, notably Dark Caracal, and was used in an operation referred to as "Operation Manul". Its deployment frequently involves spear‑phishing or supply‑chain vectors that deliver the bundled Delphi/C++ executable. Although specific configuration details vary by campaign, the malware consistently demonstrates advanced persistence mechanisms, lateral movement capabilities, and a strong focus on exfiltrating sensitive data from diverse industrial control environments.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the high‑level operational profile of Bandook is moderate; multiple independent reports (EFF, Lookout, CheckPoint) confirm its use by targeted campaigns. However, detailed technical data such as exact persistence vectors, C2 protocol specifics, and embedded obfuscation techniques are incomplete, limiting granular detection rule development.
Bandook is a commercially available RAT, written in Delphi and C++, that has been available since at least 2007. It has been used against government, financial, energy, healthcare, education, IT, and legal organizations in the US, South America, Europe, and Southeast Asia. Bandook has been used by Dark Caracal, as well as in a separate campaign referred to as "Operation Manul".(Citation: EFF Manul Aug 2016)(Citation: Lookout Dark Caracal Jan 2018)(Citation: CheckPoint Bandook Nov 2020)