Bulbature, beneath the waves of GobRAT
ID: 6cfc0a63-4f5c-5f29-ace3-121565d26474
STIX ID: report--6cfc0a63-4f5c-5f29-ace3-121565d26474
Feed Name: Sekoia.io Blog
Date Published: 2024-10-02
Date Updated: 2026-04-29
Author: Sekoia TDR, Amaury G. and Felix Aimé
Since mid‑2023 Sekoia TDR tracked an active infrastructure that compromises internet‑exposed edge devices, installing GobRAT and Bulbature to turn them into Operational Relay Boxes (ORBs) used for on‑demand proxying, DDoS and large‑scale exploitation; the report documents 63 servers (20 active at cut‑off), staging and admin interfaces, extensive bash installation scripts, C2/dispenser lists, over 74,944 exported compromised hosts in one snapshot and large asset lists totaling ~22.6M entries, and provides IPs, domains and malware hashes while attributing the activity with high confidence to Chinese operators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
