BOOKWORM is a threat actor associated with the use of DLL side-loading to execute malicious payloads through legitimate processes. Reported tradecraft includes side-loading malicious DLL components into trusted security-related executables such as Microsoft Malware Protection and Kaspersky Anti-Virus processes, indicating an emphasis on blending malicious execution with legitimate software behavior for defense evasion and execution. BOOKWORM has also used Base64 encoding to obfuscate payloads, consistent with efforts to hinder static analysis and detection. High-confidence reporting in the available material supports DLL side-loading and payload obfuscation as characteristic techniques, but does not provide sufficient corroborated detail to attribute the actor to a specific country, define broader victimology, or establish additional aliases, sub-groups, or motivations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses Base64 payload obfuscation.
Uses DLL side-loading into legitimate security-related processes to execute payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.