Buhtrap is a Windows malware family and associated intrusion toolkit historically linked to a Russian-speaking financially motivated threat actor that initially targeted banks and businesses in Russia, especially core banking environments, and later expanded into espionage-oriented operations against governmental organizations in Eastern Europe and Central Asia. The malware has been used as the group’s principal backdoor and has appeared in campaigns that blended crimeware tradecraft with techniques more commonly associated with advanced persistent threat activity.
Operationally, Buhtrap infections have been delivered through malicious documents that act as lures and drop NSIS-based installers. Decoy content has varied by target set, including business-themed documents, banking-themed material, and government-themed lures. The NSIS installers have been used to deploy the main backdoor, establish persistence, and launch additional modules. Observed auxiliary components include a credential-harvesting grabber that steals passwords from browsers and mail clients, as well as downloader and shellcode stages used to retrieve or launch further payloads.
Buhtrap campaigns have also demonstrated defense-evasion and privilege-escalation tradecraft. The operators have used valid code-signing certificates, DLL side-loading through legitimate applications, firewall-rule modification to permit command-and-control traffic, and Windows local privilege escalation exploits. Known exploitation associated with Buhtrap includes use of CVE-2015-2387 and later CVE-2019-1132, a win32k local privilege escalation vulnerability. Reporting has linked the CVE-2019-1132 exploit to exploit developer Volodya, illustrating the ecosystem in which specialized exploit authors supply tooling to both crimeware and espionage customers.
In some operations, Buhtrap-related activity included Meterpreter delivered via Metasploit, including command-and-control over DNS tunneling. The family is therefore best understood not as a single standalone implant only, but as the core backdoor within a broader modular intrusion set used for initial compromise follow-on activity, credential theft, persistence, and post-compromise control.
Buhtrap is most strongly associated with attacks on financial institutions, particularly banks and core banking systems, but later campaigns also targeted government entities. Its evolution from bank-focused cybercrime to state-aligned or espionage-like targeting is a notable example of overlap between criminal tooling, outsourced exploit development, and intelligence-style operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Throughout the years, packages with different functionalities appeared. Recently, we found two new packages that are worth describing as they deviate from the typical toolset. ... We’ve seen them exploit old vulnerabilities such as CVE-2015-2387. However, they were always known vulnerabilities. | Throughout our tracking, we’ve seen this group deploy its main backdoor as well as other tools against various victims... One of the first malicious samples we analyzed that targeted governmental organizations was a sample ... This NSIS installer downloads the regular package containing the Buhtrap backdoor.
In that case, we observed Buhtrap using a local privilege escalation exploit, CVE-2019-1132, against one of its victims. The exploit abuses a local privilege escalation vulnerability in Microsoft Windows, specifically a NULL pointer dereference in the win32k.sys component. | Throughout our tracking, we’ve seen this group deploy its main backdoor as well as other tools against various victims... One of the first malicious samples we analyzed that targeted governmental organizations was a sample ... This NSIS installer downloads the regular package containing the Buhtrap backdoor.
CVE-2015-2546 Classification: 1-Day Basic Description: Use-After-Free in xxxSendMessage (tagPOPUPMENU) ... Found in the following Malware samples: Ursnif, Buhtrap | Found in the following Malware samples: Ursnif, Buhtrap
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Throughout our tracking, we’ve seen this group deploy its main backdoor as well as other tools against various victims... One of the first malicious samples we analyzed that targeted governmental organizations was a sample ... This NSIS installer downloads the regular package containing the Buhtrap backdoor.
Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK techniques Tactic ID Name Description Persistence T1053 Scheduled Task Some of the packages create a scheduled task to be executed periodically.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware targeting core banking systems; also listed among Russian-speaking PC trojans.
Referenced only as a historical example of malware source code being leaked after disputes over profit sharing.
Referenced as a major banking-focused malware/cybercrime operation active against Russian financial institutions.
Malware/crimeware family cited as using Volodya-linked Windows LPE exploits; also referenced in relation to later cyber-espionage activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.