Bugat is a Windows banking trojan family associated with large-scale financial cybercrime and closely linked to the later Cridex and Dridex malware lines. Active from around 2010, it was designed to automate theft of confidential personal and financial information from infected systems, especially online banking credentials. Reported functionality includes hijacking browser or banking sessions, presenting fraudulent banking pages to victims, and enabling unauthorized electronic funds transfers using stolen credentials. Later variants and descendants evolved into modular malware with stronger anti-detection features and, in some cases, support for installing additional payloads including ransomware.
Bugat has been tied to botnet-enabled fraud operations that used infected hosts, internal control panels, and money mule networks to monetize stolen banking access. U.S. law-enforcement actions have alleged leadership and operational roles by members of Evil Corp, including Maksim Yakubets, and have linked Bugat, Cridex, and Dridex naming to different stages of the same broader malware lineage. Reporting also connects Bugat and related Feodo-family development to actors associated with Russian-speaking cybercrime ecosystems.
The malware targeted individuals and organizations, including banks, businesses, and other institutions, with financial services as a primary victim sector. Distribution and infrastructure overlap have been observed with major criminal ecosystems such as Avalanche, and later Dridex variants were widely spread through phishing campaigns using malicious attachments and macro-enabled documents. Bugat is best understood as an early banking-trojan family whose codebase and operational model contributed directly to the emergence of Dridex as a major successor threat.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Bugat malware was allegedly designed to automate the theft of confidential personal and financial information, such as online banking credentials, and facilitated the theft of confidential personal and financial information by a number of methods.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multifunction financial malware family designed to steal confidential personal and financial information, especially online banking credentials. It used techniques such as session hijacking and fake banking webpages, was crafted to evade antivirus and other protections, and later versions added functionality to assist in installing ransomware.
Malware family listed as hosted on Avalanche infrastructure; associated in the alert with credential theft and targeting financial institutions.
Financial malware described as less widespread than ZeuS but equally sophisticated and expanding quietly across the internet.
Banking-malware family/cluster referenced as being hosted on Avalanche infrastructure (with multiple aliases listed in the source).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.