logo

A look at the recent BuleHero botnet payload

ID: 4dcbc565-8b11-55be-a806-337021592f34

STIX ID: report--4dcbc565-8b11-55be-a806-337021592f34

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report analyzes the BuleHero botnet, a modular malware campaign that uses leaked ShadowBroker SMB exploits (EternalBlue/EternalRomance/EternalChampion), many web-application RCEs (Tomcat, Struts, WebLogic, Drupal, Solr, ThinkPHP), credential theft (Mimikatz), and remote execution tools (PsExec/WMIC) to spread laterally, deploy XMRig miners and Gh0st RAT, persist via services and scheduled tasks, and manipulate firewall/associations; the document includes detailed IOCs (URLs, IPs, and file hashes) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.