EvilBunny is a Windows backdoor associated with Lazarus Group activity, including malware used in the 2016 Bangladesh Bank SWIFT intrusion. It has exploited CVE-2011-4369 in Adobe Reader for execution. EvilBunny performs host and security-product reconnaissance through process enumeration, WMI-based system discovery, and queries for installed antivirus software. It performs sandbox-evasion checks using system-time and tick-count APIs, establishes persistence through Registry Run keys, and executes commands through Windows Scheduled Tasks. It also deletes its initial dropper following environment checks to reduce forensic evidence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
EvilBunny has exploited CVE-2011-4369, a vulnerability in the PRC component in Adobe Reader.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware ... [was] catalog[ed] under multiple designations including Trojan.Contopee and a variant of the backdoor known as “EvilBunny.”
The malware ... [was] catalog[ed] under multiple designations including Trojan.Contopee and a variant of the backdoor known as “EvilBunny.”
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Upon execution, the payload dropped a first-stage loader that established persistence via registry run keys and scheduled tasks.”
Several entries refer generically to command-line interfaces, shell commands, scripting engines, or script execution without always specifying the exact interpreter.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Upon execution, the payload dropped a first-stage loader that established persistence via registry run keys and scheduled tasks.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Upon execution, the payload dropped a first-stage loader that established persistence via registry run keys and scheduled tasks.”
Many entries explicitly describe deleting artifacts 'to cover tracks,' 'evade detection,' 'remove evidence,' 'reduce their footprint,' or as part of 'post-intrusion cleanup process.' Examples include APT28 deleting files to cover tracks, FIN5 using SDelete to clean up the environment, and Dragonfly deleting operational files as part of cleanup.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
“During this window, the intruders mapped the bank’s internal network topology [and] identified workstations connected to the SWIFT Alliance system.”
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Examples include 'Action RAT can use WMI to gather AV products installed on an infected host,' 'Bumblebee can use WMI to gather system information,' and 'Volt Typhoon has leveraged WMIC for execution, remote system discovery.'
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
“Network traffic analysis showed the malware communicating with C2 servers over HTTPS using self-signed certificates.”
“[The malware used] fallback channels over DNS tunneling for environments where direct outbound connections were restricted.”
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor variant identified in connection with the Bangladesh Bank intrusion. The described implant provided covert command-and-control and supported persistent access, keylogging, screen capture, file exfiltration, and arbitrary command execution.
Malware that establishes persistence through Run keys in HKLM or HKCU.
Malware that gathers time metrics via Windows APIs as part of sandbox detection.
Dropper malware that deletes its initial dropper after environment checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.