Buhtrap is a Windows backdoor associated with the Buhtrap cybercrime and espionage group. Initially linked to financially motivated intrusions against Russian businesses and financial institutions, the group later targeted governmental entities in Eastern Europe and Central Asia. Buhtrap campaigns have used malicious documents with benign, contextually relevant decoy content to deliver NSIS-based droppers that install the primary backdoor. The malware ecosystem has employed Windows local privilege-escalation vulnerabilities, including CVE-2019-1132, to obtain elevated execution. Campaign components have established persistence, stolen passwords from browsers and email clients, exfiltrated those credentials to command-and-control infrastructure, and used DLL side-loading through legitimate applications to launch the main backdoor. Buhtrap operators have also used valid code-signing certificates and other tools to reduce detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Throughout the years, packages with different functionalities appeared. Recently, we found two new packages that are worth describing as they deviate from the typical toolset. ... We’ve seen them exploit old vulnerabilities such as CVE-2015-2387. However, they were always known vulnerabilities. | Throughout our tracking, we’ve seen this group deploy its main backdoor as well as other tools against various victims... One of the first malicious samples we analyzed that targeted governmental organizations was a sample ... This NSIS installer downloads the regular package containing the Buhtrap backdoor.
In that case, we observed Buhtrap using a local privilege escalation exploit, CVE-2019-1132, against one of its victims. The exploit abuses a local privilege escalation vulnerability in Microsoft Windows, specifically a NULL pointer dereference in the win32k.sys component. | Throughout our tracking, we’ve seen this group deploy its main backdoor as well as other tools against various victims... One of the first malicious samples we analyzed that targeted governmental organizations was a sample ... This NSIS installer downloads the regular package containing the Buhtrap backdoor.
CVE-2015-2546 Classification: 1-Day Basic Description: Use-After-Free in xxxSendMessage (tagPOPUPMENU) ... Found in the following Malware samples: Ursnif, Buhtrap | Found in the following Malware samples: Ursnif, Buhtrap
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tools SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit
Throughout our tracking, we’ve seen this group deploy its main backdoor as well as other tools against various victims... One of the first malicious samples we analyzed that targeted governmental organizations was a sample ... This NSIS installer downloads the regular package containing the Buhtrap backdoor.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK techniques Tactic ID Name Description Persistence T1053 Scheduled Task Some of the packages create a scheduled task to be executed periodically.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Banking malware targeting core banking systems; also listed among Russian-speaking PC trojans.
Referenced only as a historical example of malware source code being leaked after disputes over profit sharing.
Referenced as a major banking-focused malware/cybercrime operation active against Russian financial institutions.
Malware/crimeware family cited as using Volodya-linked Windows LPE exploits; also referenced in relation to later cyber-espionage activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.