Bandook is a long-running Windows remote access trojan first observed in 2007 and continuously developed in later variants. It is a commercially available RAT that has appeared in both criminal and targeted espionage operations, including activity associated with Dark Caracal and the Operation Manul campaign targeting Kazakh dissidents, journalists, lawyers, and associates connected to disputes with the government of Kazakhstan. Bandook has also been distributed through user-driven infection chains involving lure documents with malicious VBA macros and, in later reporting, through a PDF-based lure leading victims to retrieve and extract an archived payload.
Bandook provides broad post-compromise remote administration and surveillance functionality. Documented capabilities include keylogging, screen capture, remote desktop monitoring and control, file collection and upload over the command-and-control channel, file read and write operations, file deletion, process termination, registry manipulation, execution of additional files and DLL functionality, and collection of host and network information such as the victim’s public IP address. Some variants also support browser cookie theft and abuse of browser sessions by interacting with Chrome, Edge, and Firefox data and settings. Bandook can download additional modules to extend functionality, including components for surveillance and credential-related collection.
Execution and evasion tradecraft includes use of PowerShell loaders, decoding of PowerShell scripts, malicious VBA code, and process hollowing or similar replacement of legitimate Windows processes with the Bandook payload. Reported variants have launched or injected into legitimate processes such as browser processes and system utilities, and Bandook has been observed using native Windows APIs including ShellExecuteW. Command-and-control traffic has been protected with AES encryption in some variants.
Persistence on Windows has been achieved through Registry-based autostart mechanisms, including Run-key persistence documented in Dark Caracal-linked activity. Newer variants have also used multiple Registry-backed control codes to coordinate execution and persistence, with persistence options including Run and other Windows autostart settings. Overall, Bandook is best characterized as a mature Windows RAT with modular surveillance, file theft, remote control, and persistence capabilities that has remained operationally relevant across multiple campaigns and actor sets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Dark Caracal's version of Bandook adds a registry key to HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run for persistence.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
33 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
This action executes a Python file. The main command is @0128, which calls a ShellExecute function to run a Python file {Parent directory}\Lib\dpx.pyc with arguments Arg2~Arg6.
Before the injection, a registry key is created to control the behavior of the payload. The key name is the PID of msinfo32.exe, and the value contains the control code for the payload.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The injector component decrypts the payload in the resource table and injects it into msinfo32.exe.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Figure 4: Traffic capture and AES decrypted data of the victim information.
The phishing... often took the form of an email purporting to contain an invoice or a legal document with an attachment containing a blurry image.
The injector component decrypts the payload in the resource table and injects it into msinfo32.exe.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
The following is a list of overall features available in this version of Bandook: ● Audio recording
First, Bandook sends victim information to its C2 server... If the C2 server is available, Bandook receives commands from the server, including *DJDSR^, @0001, @0002, and so on.
298 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
70 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bandook is a remote access trojan (RAT) that allows attackers to control infected systems remotely.
A backdoor family the attributed threat actor is known to use in attacks; mentioned as related tooling rather than the main malware in this campaign.
A long-running remote access trojan for Windows that injects its payload into msinfo32.exe, establishes persistence via registry keys and dropped copies, communicates with a C2 server using numerous commands, downloads additional modules such as fcd.dll and pcd.dll, steals information including browser cookies, manipulates files and registries, executes files including Python payloads, enables remote screen monitoring and victim control, kills processes, and can uninstall itself.
Bandook is a Windows remote access trojan/spyware used in an ongoing Dark Caracal campaign. The report describes capabilities including webcam access, screen recording, mouse control, remote desktop, file operations, credential-related functions, and downloading additional DLLs for added functionality.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.