Bandidos is the name given to a long-running cyberespionage campaign centered on the Bandook remote access trojan. The activity has been assessed as active since at least 2015 and primarily targets corporate environments in Spanish-speaking countries, with the overwhelming majority of observed detections in Venezuela. Victim organizations have included companies in manufacturing, construction, health care, software services, and retail, indicating broad corporate espionage rather than a single narrowly defined vertical focus. The campaign commonly relies on phishing emails delivering PDF lures that direct victims to password-protected archives hosted on cloud storage services, sometimes via URL shorteners. The delivered malware uses a Delphi-based dropper that decrypts and injects Bandook into Internet Explorer processes using process hollowing. Persistence is established through Windows autorun mechanisms and copied payloads in user-space locations. The malware communicates with command-and-control infrastructure over TCP and supports a large command set for remote tasking. Bandidos operators use modular Bandook components to expand surveillance and collection capabilities. Documented functionality includes system reconnaissance, file operations, shell access, screenshot capture, webcam and audio recording, Wi-Fi information gathering, USB data theft, and browser-focused credential interception. One module has been observed manipulating Google Chrome to install a malicious extension that captures credentials entered into web forms for later exfiltration. The campaign’s tooling and victimology support an espionage assessment rather than financially motivated crime. The activity has also been linked to older Bandook-related operations and overlaps reported in research on Bandook usage, including references to Operation Manul and Dark Caracal. No high-confidence attribution to a specific state or named intrusion set is established in the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
69 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Outlaw motorcycle gang described as concealing criminal activity within legitimate businesses and profiting from prostitution, drug trafficking, arms trafficking, and protection racketeering.
An espionage-oriented campaign active since at least 2015 targeting corporate networks in Spanish-speaking countries, especially Venezuela, using Bandook RAT delivered via malicious emails with PDF attachments linking to password-protected archives.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.