logo

BUGHATCH Malware Analysis

ID: 85ac23cf-1fb5-5e8b-9a2f-bbdd75340030

STIX ID: report--85ac23cf-1fb5-5e8b-9a2f-bbdd75340030

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2022-09-09

Date Updated: 2026-04-27

...
...

Elastic Security Labs provides a technical analysis of BUGHATCH, an in-memory implant used in the CUBA ransomware campaign, detailing how an obfuscated PowerShell loader decodes and executes shellcode, the implant’s information-collection and SeDebugPrivilege token elevation behavior, its custom HTTP(S) communication protocol with a 2-byte XOR session key, multithreaded command execution (reflective PE loading, remote shellcode execution, command/PowerShell execution, process migration/impersonation), and includes a YARA rule and MITRE ATT&CK mappings to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.