New Bandook RAT Variant Resurfaces, Targeting Windows Machines
ID: 565d22d8-b095-5a49-94cf-ba183c15bb91
STIX ID: report--565d22d8-b095-5a49-94cf-ba183c15bb91
Feed Name: The Hacker News
Threat Score
**Bandook RAT campaign (Oct 2023 observed)** — Fortinet FortiGuard Labs observed a phishing-based distribution of a new Bandook variant delivered via a PDF that links to a password-protected .7z archive; after extraction the malware injects into msinfo32.exe, establishes registry persistence, connects to C2 servers for additional payloads and instructions, and conducts file manipulation, registry changes, information theft, and remote control activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
