BetaBot, also known as Neurevt, is a Windows malware family that emerged in late 2012 as a banking Trojan and later evolved into a multifunction infostealer and bot. It is designed to steal sensitive information from infected systems and support broader post-compromise activity under operator control. Documented capabilities include browser form grabbing, theft of credentials from FTP and mail clients, arbitrary command execution, malware download, DDoS functionality, USB propagation, and persistence. Some versions also incorporated a cryptocurrency mining component. Administrative-panel features observed across versions indicate support for bot management, tasking, updates, file retrieval, SOCKS proxying, URL visitation, and collection of form-grabber logs.
Observed intrusion chains show BetaBot being delivered through phishing campaigns using weaponized Microsoft Office documents, including RTF-based lures exploiting CVE-2017-11882 in the Equation Editor component. It has also been delivered through exploit-kit activity, including Sweet Orange campaigns exploiting CVE-2014-6332, and through malware distribution operations such as RATicate, which used malicious spam and NSIS-based loaders to deploy multiple commodity stealers and RATs including BetaBot. In these chains, BetaBot has been unpacked by droppers or loaders and then injected into running Windows processes for execution.
On infected hosts, BetaBot has been observed unpacking its payload and injecting into child or legitimate processes, commonly Explorer.exe, as part of execution and evasion. It establishes persistence through autorun mechanisms and in some cases scheduled tasks. It also modifies permissions on persistence artifacts and uses API hooking to conceal persistence from common administrative and monitoring tools. Anti-analysis and self-protection features include anti-debugging, anti-virtualization and anti-sandbox checks, detection of numerous security products, interference with security tooling, DNS blocking of security vendors, and a BotKiller capability intended to identify or suppress competing malware.
BetaBot has appeared in criminal malware ecosystems both as a primary payload and as a secondary task distributed by other malware. It has been associated with broad financially motivated activity rather than a single exclusive operator, and has been seen alongside families such as LokiBot, Formbook, AgentTesla, NetWire, Andromeda, and other commodity crimeware. Targeting has included enterprise environments and organizations in multiple regions, with phishing lures often themed around business transactions. The family is best characterized as a mature Windows infostealer with banking-Trojan heritage, modular operator tasking, and strong defense-evasion features.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Betabot exploits an 18-year-old vulnerability in the Equation Editor tool in Microsoft Office... Infection Vector: CVE-2017-11882 Exploit-Weaponized Document... Opening the weaponized RTF documents triggers the Equation Editor exploit (CVE-2017-11882) and executes dqfm.cmd. | In the past few weeks, the Cybereason SOC has detected multiple Betabot (aka Neurevt) infections in customer environments. Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012.
The first encounter I had with this CVE in exploit kit, was in the Sweet Orange... already containing CVE-2014-6332... Sweet Orange firing CVE-2014-6332 and DarkShell Call back... Here a more "standard" Sweet Orange : CVE-2014-6332 fired by Sweet Orange - And Betabot call back... Neutrino Firing CVE-2014-6332... Archie... CVE-2014-6332... Flash EK firing CVE-2014-6332... NB : it's in RIG and Angler | Here a more "standard" Sweet Orange : CVE-2014-6332 fired by Sweet Orange - And Betabot call back. 2014-11-21
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
These campaigns, detailed in our previous report, distributed payloads that included AgentTesla, Formbook, Lokibot, Netwire and Betabot.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
I found it spread as a tasks in a Betabot and in an Andromeda spread via RIG fed by at least one HilltopAds malvertising.
We tracked multiple malicious spam (“malspam”) email campaigns from the group, with attached installers that usually posed as documents related to financial transactions.
A secondary persistence mechanism that was implemented via Windows Task Scheduler was also observed in some infections: ... schtasks.exe' /CREATE /SC ONLOGON /TN 'Windows Update Check - [variable]' /TR 'C:\ProgramData\[path_to_file]
Opening the weaponized RTF documents triggers the Equation Editor exploit ( CVE-2017-11882 ) and executes dqfm.cmd, which spawns hondi.cmd.
A secondary persistence mechanism that was implemented via Windows Task Scheduler was also observed in some infections: ... schtasks.exe' /CREATE /SC ONLOGON /TN 'Windows Update Check - [variable]' /TR 'C:\ProgramData\[path_to_file]
A secondary persistence mechanism that was implemented via Windows Task Scheduler was also observed in some infections: ... schtasks.exe' /CREATE /SC ONLOGON /TN 'Windows Update Check - [variable]' /TR 'C:\ProgramData\[path_to_file]
The loader will unpack the payload and inject it into its own child process... In most cases, the main payload will first be injected into a second instance of Explorer.exe. However, in one of the incidents, we observed Betabot injecting itself into a McAfee process called “shtat.exe”.
Betabot’s main features include... Robust Userland Rootkit (x86/x64)... Once Betabot is executed, it make extensive usage of API hooking to hide the persistence from regedit, Sysinternal’s Autoruns and other monitoring tools.
One of the key techniques this crypter uses is multiple layers of encryption. Because of this we are calling it “OnionCrypter”.
A crypter encrypts a program, so it looks like meaningless data and it creates an envelope for this encrypted program also called a stub.
attached installers that usually posed as documents related to financial transactions
The loader will unpack the payload and inject it into its own child process... In most cases, the main payload will first be injected into a second instance of Explorer.exe. However, in one of the incidents, we observed Betabot injecting itself into a McAfee process called “shtat.exe”.
Delete traces of the original RTF document by enumerating all the Resiliency registry keys and deleting them... hondi.cmd Deleting traces by deleting the resiliency registry entry
Betabot will attempt to determine if it is executed in a virtual environment by querying the registry and looking for the names of virtual machine vendors such as VMware, VirtualBox and Parallels... Another trick used to determine if the environment is virtual is to obtain a handle to \\Device\\Harddisk0\\Partition and \\??\\PHYSICALDRIVE0.
Betabot will attempt to determine if it is executed in a virtual environment by querying the registry and looking for the names of virtual machine vendors such as VMware, VirtualBox and Parallels... Another trick used to determine if the environment is virtual is to obtain a handle to \\Device\\Harddisk0\\Partition and \\??\\PHYSICALDRIVE0.
The payloads of the campaigns using both types of installers delivered the same families of remote administration tool (RAT) and information stealing malware, and they shared the same command and control (C&C) infrastructure.
146 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Explicitly described as incidental implant activity on devices behind the routers, not connected to Zhadnost deployment.
Malware family delivered in RATicate campaigns; the infrastructure analysis in the article maps multiple C2 paths to Betabot payloads.
Likely a bot/botnet malware/tool listed as detectable via SHA-256 hash.
Betabot is a sophisticated infostealer that began as a banking Trojan and evolved into a multifunction malware platform. The content describes capabilities including browser form grabbing, FTP and mail client credential theft, banker functions, DDoS, USB infection, userland rootkit features, arbitrary shell command execution, downloading additional malware, persistence, process injection, API hooking, anti-debugging, anti-VM/sandbox checks, antivirus detection/disablement, and bot-killing of competing malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.