Bandook is a Windows remote-access trojan used for espionage-oriented operations, including activity associated with the Lebanon-linked Dark Caracal threat group. It has been deployed alongside the GoCaracal framework, including against a Venezuelan communications organization in 2026, indicating continued use within Dark Caracal’s tooling. Bandook supports keylogging, desktop screenshot capture and upload, local file collection and upload over its command-and-control channel, and public IP-address discovery. It can delete files and has used process hollowing by replacing a legitimate browser process with its payload to evade detection. Observed delivery and execution tradecraft includes malicious VBA-enabled lure documents that induce users to enable macros, as well as PowerShell-based loaders. An updated variant randomized command identifiers and obfuscated plugin export names, hindering signature-based detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The June 2026 intrusion affecting a communications organization in Venezuela resulted in deployment of GoCaracal and an updated version of Bandook.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
The infection chain features a PDF containing a URL that leads to an encrypted RAR file which installs Bandook malware. The group uses Spanish-languages lures to distribute a known – but infrequently used – remote access trojan (RAT) called Bandook.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
“Their tactics include phishing, malicious websites, and trojanized mobile applications.”
“The campaign begins with Spanish-language financial and tax lures sent through phishing emails.”
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
attempted to lure victims into enabling malicious macros within email attachments... prompted victims to accept macros... Word documents containing malicious macros.
The content is a MITRE ATT&CK-style listing of many malware families and threat groups using Windows/native OS APIs for execution, injection, discovery, anti-debugging, and other actions, ending with 'NtCreateProcess' and 'fork()'.
Before the injection, a registry key is created to control the behavior of the payload. The key name is the PID of msinfo32.exe, and the value contains the control code for the payload.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
“Sequential command identifiers ... were replaced with randomised strings, and plugin export names were obfuscated with generic labels.”
Figure 4: Traffic capture and AES decrypted data of the victim information.
The phishing... often took the form of an email purporting to contain an invoice or a legal document with an attachment containing a blurry image.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
339 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
79 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An updated version of the Bandook backdoor was deployed alongside GoCaracal in the cited Dark Caracal intrusion.
Backdoor historique déployé parallèlement à GoCaracal dans la campagne attribuée à Dark Caracal.
An established backdoor in Dark Caracal's toolkit, delivered alongside GoCaracal in the Venezuelan communications-sector intrusion.
A long-used backdoor in Dark Caracal's toolkit, delivered alongside GoCaracal during the reported Venezuelan communications-organization intrusion.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.