Bisonal is a Windows remote-access trojan associated with the cyberespionage group Tonto Team, also known as CactusPete. The family and its DoubleT variant have undergone development for more than a decade. Bisonal has been used against government, military, defense-related, and technology organizations in South Korea, Japan, and Russia, and has also been deployed against procurement and cybersecurity consulting organizations in Eastern Europe.
Bisonal supports host reconnaissance and remote control. Its capabilities include enumerating running processes, inspecting network configuration, and checking system time. The DoubleT variant collects host and account identifiers, local IP addresses, proxy settings, uptime, and system-language information. It can enumerate and terminate processes, provide remote command-shell access, create files, and download and execute additional payloads. Collected host information and command results are transmitted through command-and-control communications. Variants have used raw sockets or web protocols, with XOR or RC4 protecting communications and strings. Bisonal uses Base64 encoding, while DoubleT additionally uses Base32 and a modified RC4 implementation.
Delivery has included spearphishing attachments generated with the Royal Road RTF weaponizer, which exploits Microsoft Equation Editor vulnerabilities. Bisonal has also been deployed following exploitation of Microsoft Exchange servers in ProxyLogon campaigns. Its deployment components create Visual Basic scripts, disguise malicious scripts as image files, and delete droppers and scripts after installation. Persistence is established through Registry-based autostart entries, with some variants using the Windows Rundll32 utility to execute the payload. Bisonal droppers have also appended random data to deployed binaries to change their hashes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Microsoft was spurred to release out-of-band patches for the exploited bugs, known collectively as ProxyLogon, which are being tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
Royal Road is a tool that generates RTF files that exploit the Microsoft Office Equation Editor vulnerabilities (CVE-2017-11882, CVE-2018-0798, CVE-2018-0802).
ADに対するマルウェアの設置-脆弱性確認- MS17-010の脆弱性の有無を確認している。... “192.168.66.50 is not patched”と出力されている通り、ADはMS17-010のパッチが適用されていないことを表している。
下記が悪用されて、圧縮ファイル内のドロッパーが起動した。⚫CVE-2018-20250: WinRarに存在する任意のパスにファイルを設置される脆弱性
May 2018: a new wave of targeted attacks abusing CVE-2018-8174 (this exploit has been associated with the DarkHotel APT group, as described on Securelist), with diplomatic, defense, manufacturing, military and government targets in Asia and Eastern Europe;
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CactusPete attacks implanted ShadowPad "along with a variant of the Bisonal remote-access trojan (RAT)."
'APT10 is said to be behind the campaigns' ... 'Code similarity with BISONAL malware (hardcorded version information)'
Bisonal is another example. It is a backdoor. The malware can be split into two components: the main module, communication module... The malware is capable of: Listing and controlling processes, Creating and deleting files, Creating a remote shell, Downloading and executing files.
Operation Bitter Biscuitの特徴 ⚫標的国: 韓国、ロシア、日本 ⚫標的業種: 政府関係、軍事・国防関連企業 (IT企業も攻撃されたという情報有り[4]) ⚫マルウェア: Bisonal
Operation Bitter Biscuitの特徴 ⚫標的国: 韓国、ロシア、日本 ⚫標的業種: 政府関係、軍事・国防関連企業 (IT企業も攻撃されたという情報有り[4]) ⚫マルウェア: Bisonal
Як результат, комп'ютер жертви буде уражено шкідливою програмою Bisonal... Більше того, шкідлива програма Bisonal, як приклад, є інструментом групи TontoTeam (UAC-0018).
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network. Specific examples include use of network layer protocols, such as the Internet Control Message Protocol (ICMP), transport layer protocols, such as the User Datagram Protocol (UDP), session layer protocols, such as Socket Secure (SOCKS), as well as redirected/tunneled protocols, such as Serial over LAN (SOL).
181 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
97 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular backdoor/trojan with main and communication modules. It supports process control, file creation/deletion, remote shell access, downloading additional executables, beaconing, and data theft over HTTP-based client/server C2.
A backdoor RAT associated with Chinese threat actors, used as the payload delivered via malicious Office documents. It provides long-term remote access and has evolved with capabilities for file searching and exfiltration, anti-analysis and detection evasion, and generally unrestricted system control.
Previously known malware referenced only as historical context for Tonto Team activity against Russian organizations.
Backdoor family attributed to Tonto Team. The report references a previously documented Bisonal sample communicating with offices-update[.]com and compares its network requests with those of Bisonal.DoubleT.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.