Bedep is a Windows malware family most widely known as a downloader and loader tightly associated with the Angler exploit kit during 2014 and 2015. It was delivered primarily through exploit-driven malvertising and Angler landing pages, including campaigns exploiting Adobe Flash vulnerabilities such as CVE-2015-0311. Bedep has been characterized as a largely fileless loader with resident components that can retrieve additional malware and, in many campaigns, conduct ad-fraud or click-fraud activity. Observed secondary payloads delivered through Bedep-linked infection chains have included banking malware, ransomware, credential-stealing malware, and point-of-sale malware such as Vawtrak, Pony, CryptXXX, Ursnif, Ramnit, Reactor Bot, and AbaddonPOS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Back in the 0-Day Let's start a little more than a year ago with the Angler Flash 0-day (CVE-2015-0310)... It started a year ago with the Adobe Flash 0-Day that was incorporated into Angler (CVE-2015-0310). | Bedep is a malware downloader that is exclusive to Angler. This post will discuss the Bedep side of Angler and draw some pretty clear connections between Angler and Bedep.
Upon successful exploitation, we observed a new variant of the Bedep Trojan getting dropped and executed on the victim machine.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Bedep could be described as a fileless loader with a resident module that can optionally perform AdFraud.
After that, Bedep acts differently. You'll see Bedep contacting 95.211.205[.]228 after Bedep detects it's running on a VM, and it will download different malware. As usual, no CryptXXX ransomware when doing the Angler EK/Bedep infection with a VM, and any click-fraud traffic is a ruse.
After that, Bedep acts differently. You'll see Bedep contacting 95.211.205[.]228 after Bedep detects it's running on a VM, and it will download different malware. As usual, no CryptXXX ransomware when doing the Angler EK/Bedep infection with a VM, and any click-fraud traffic is a ruse.
Some resulting in Bedep not trying to contact the C&C, some where the positive check end up with a different seed for the Bedep DGA redirecting spotted machines in a dedicated instance.
You'll see Bedep contacting 95.211.205[.]228 after Bedep detects it's running on a VM, and it will download different malware.
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bedep is a modular downloader and ad-fraud botnet known for using a highly sophisticated domain generation algorithm seeded with European Central Bank foreign exchange rates to hide and rotate its command-and-control infrastructure.
Malware in the Angler EK infection chain that performs post-infection network activity, shows VM-aware behavior, and can lead to delivery of CryptXXX on normal hosts while downloading different malware or click-fraud-related payloads when VM detection occurs.
Referenced as malware using a domain generation algorithm (DGA).
Bedep is referenced as another malware family with a DGA seeded from nondeterministic external data sources.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.