Bookworm is a modular Windows remote access Trojan associated with long-running cyberespionage activity in Southeast Asia. First observed in 2015, it has been used to target government and related organizations, initially with a strong concentration on Thailand and later in broader ASEAN-linked operations. Bookworm has been attributed with high confidence to the Chinese threat actor Stately Taurus, and reporting also notes overlap with tradecraft historically associated with Mustang Panda. The malware has remained operationally relevant for years, with newer variants preserving the same core architecture while changing packaging and loader components.
Bookworm functions primarily as a RAT and backdoor that gives operators persistent remote control of compromised systems. Its built-in functionality includes keylogging and clipboard theft, and it can expand its capabilities by loading additional modules from command-and-control infrastructure. Reported capabilities include arbitrary command execution, file upload and download, and data exfiltration. A dedicated logging component has been observed creating a hidden window while collecting keystrokes and clipboard contents, reflecting an emphasis on stealth during collection.
A defining characteristic of Bookworm is its modular, staged execution chain and frequent abuse of legitimate software for DLL sideloading. Operators have used legitimate signed executables to load malicious DLL components, including execution within trusted security product processes. Recent variants also use shellcode-loading methods in which payload data is encoded as UUID strings and executed through legitimate Windows APIs, indicating incremental modernization rather than a full redesign.
Bookworm employs multiple persistence and defense-evasion mechanisms. Observed techniques include creation of a Windows service masquerading as a legitimate component to launch at system startup, modification of related Registry values, use of valid digital signatures or certificates to reduce suspicion, creation of hidden windows during collection, and timestamp manipulation to hinder forensic analysis. Its network communications have also been modified to resemble legitimate HTTP traffic.
Delivery has been observed through spearphishing campaigns using decoy documents and themed lures tied to current events, particularly in operations against Thai government entities. Compromised legitimate web servers have also been used to host Bookworm-related payloads and tooling. Across campaigns, Bookworm has been part of broader intrusion sets that also involved other malware families and staging tools, underscoring its role as a reusable espionage platform rather than a single isolated implant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
First observed in 2015, Bookworm functions primarily as an advanced remote access Trojan (RAT), granting its operators extensive control over compromised systems.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
have access to compromised web servers that could facilitate strategic web compromise (SWC) as an attack vector in the future | We also speculate that these threat actors may use strategic web compromises (SWC) as an attack vector in future campaigns using their unauthorized access to webservers.
"BOOKWORM ... execution on the heap is initiated through callback function of legitimate API functions such as EnumChildWindows or EnumSystemLanguageGroupsA"; "CLAIMLOADER ... run its shellcode through the callback function"; "PUBLOAD stager leveraged Windows API functions with callback ... to bypass anti-virus monitoring"
The decoded shellcode decrypts and loads dynamic-link libraries (DLLs) that comprise the Bookworm malware... The Bookworm malware family consists of multiple modules, each of which support the main Leader.dll module by providing additional functionality.
The payloads shown in Table 1 are loaders that contain embedded shellcode... Creating a buffer on the heap using HeapCreate and HeapAlloc... Copying shellcode to buffer on the heap... Using a callback function of a legitimate API function, such as EnumChildWindows or EnumSystemLanguageGroupsA to execute the shellcode on the heap.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.
The payloads shown in Table 1 are loaders that contain embedded shellcode... Creating a buffer on the heap using HeapCreate and HeapAlloc... Copying shellcode to buffer on the heap... Using a callback function of a legitimate API function, such as EnumChildWindows or EnumSystemLanguageGroupsA to execute the shellcode on the heap.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
Using ASCII or decoded Base64 strings that represent UUID strings. Calling UuidFromStringA to convert the decoded UUIDs to binary data, each of which represents 16 bytes of shellcode.
Encrypt original shellcode file (to be a “bin” file) and path information (to be a “path” file) by using RC4 algorithm (key is the value of “ProductID” from “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Registration”)
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
Use of large command and control (C2) infrastructure, which heavily favors dynamic DNS domains for C2 servers.
This particular PubLoad payload communicates with its C2 server by directly connecting to the IP address 123.253.32[.]15. The payload then issues an HTTP request... The HTTP request includes www.asia.microsoft.com within the host field as an attempt to masquerade as a legitimate request associated with the Windows operating system.
Threat actors have delivered Bookworm as a payload in attacks on targets in Thailand.
All other communication traffic, except for the victim information, are encrypted between server and client applications using the RC4 and compressed by LZO (Lempel–Ziv–Oberhumer) algorithm.
113 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used for keylogging and clipboard theft that creates hidden windows for stealth.
Malware referenced as part of China-linked activity targeting Asian telecom/ASEAN networks; no further details in excerpt.
... Theft of Operational Information ... BOOKWORM ... (v1.0) ...
BOOKWORM (v1.0)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.