BBSRAT is a Windows remote access trojan associated with Roaming Tiger activity and attacks against Russian organizations and Mongolian government offices. Its capabilities include enumerating running processes, listing file and directory information, deleting files and directories, querying and modifying Windows service configurations, and starting, stopping, or deleting services. It communicates with command-and-control servers through HTTP or HTTPS GET and POST requests, uses custom encryption for outbound data, and sends ZLIB-compressed data.
BBSRAT has been delivered through spear-phishing emails containing weaponized Microsoft Word documents with political and official-announcement lures. A campaign targeting Mongolian government offices between August 2015 and February 2016 exploited CVE-2012-0158 and, in later documents, CVE-2014-1761. Most documents deployed the Cmstar loader to retrieve BBSRAT, while some embedded BBSRAT directly. Execution techniques include DLL side-loading through the legitimate Citrix Single Sign-On Server executable and process hollowing within a Windows Installer process to conceal execution. Deployment has also used the Windows Expand utility to extract executable content from CAB archives. Persistence is established through Windows Registry Run autostart entries, including entries that launch a legitimate executable used for side-loading.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attacks themselves followed a consistent playbook throughout the observed timeframe; using weaponized Microsoft Word documents initially containing an exploit for only CVE-2012-0158... All of the Microsoft Word documents leveraged in these attacks used the CVE-2012-0158 and CVE-2014-1761 exploits. | All of the weaponized documents except two executed the Cmstar loader... Once Cmstar was loaded onto the victim hosts, it would attempt to retrieve a final payload... those that were available were variants of BBSRAT. The two samples not using Cmstar simply had BBSRAT embedded directly into to the weaponized document.
The newer documents containing exploits for both vulnerabilities appeared to use a publically available PoC authored by ‘HCL’, with little to no modifications made... All of the Microsoft Word documents leveraged in these attacks used the CVE-2012-0158 and CVE-2014-1761 exploits. | All of the weaponized documents except two executed the Cmstar loader... Once Cmstar was loaded onto the victim hosts, it would attempt to retrieve a final payload... those that were available were variants of BBSRAT. The two samples not using Cmstar simply had BBSRAT embedded directly into to the weaponized document.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger" is the reference for abuse of Citrix Single Sign On Server, ssonsvr.exe.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
All of the Microsoft Word documents leveraged in these attacks used the CVE-2012-0158 and CVE-2014-1761 exploits.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The initial dropper embedded in the weaponized document files were obfuscated using a subtraction cipher previously used to obfuscate strings in the NetTraveler malware family.
...while displaying a decoy document or a legitimate appearing document that is generated and presented to the user to make it appear that the weaponized document that had been executed was indeed, legitimate.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
Each of the samples collected via WildFire and VirusTotal contained significant overlaps in tactics used, tools used, as well as infrastructure for command and control channels.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
Once Cmstar was loaded onto the victim hosts, it would attempt to retrieve a final payload... those that were available were variants of BBSRAT.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named in a referenced campaign targeting Russian organizations. The survey associates that campaign with DLL hijacking through the Citrix executable ssonsvr.exe.
Remote access trojan with file and directory deletion capability.
Remote access trojan that persists via a Registry Run key, including through DLL side-loading of a legitimate executable.
Remote access trojan that uses Expand to decompress CAB files into executable content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.