logo

New Bandook RAT Variant Resurfaces, Targeting Windows Machines

ID: 565d22d8-b095-5a49-94cf-ba183c15bb91

STIX ID: report--565d22d8-b095-5a49-94cf-ba183c15bb91

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-01-05

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

**Bandook RAT campaign (Oct 2023 observed)** — Fortinet FortiGuard Labs observed a phishing-based distribution of a new Bandook variant delivered via a PDF that links to a password-protected .7z archive; after extraction the malware injects into msinfo32.exe, establishes registry persistence, connects to C2 servers for additional payloads and instructions, and conducts file manipulation, registry changes, information theft, and remote control activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.