A long-running cyberespionage operation dubbed Bandidos used the Bandook remote access trojan to infiltrate corporate networks across Spanish-speaking Latin America, with roughly 90% of observed detections concentrated in Venezuela. The campaign, active since at least 2015, relied on phishing emails carrying PDF lures that directed victims to password-protected archives containing a Delphi dropper. That dropper injected Bandook into iexplore.exe through process hollowing, established persistence via Windows Registry changes, and connected to command-and-control servers over TCP.
Researchers said the malware supported extensive surveillance and theft functions, including screenshot capture, webcam and microphone recording, USB data theft, and interception of Chrome credentials, while also downloading additional DLLs to expand capability. The 2021 variant showed notable evolution from earlier Bandook activity, including a shift from CAST-256 to GOST in the dropper, a reduced DLL set, and support for 132 commands. The infrastructure and tooling overlapped with previously documented Bandook-linked operations, including Operation Manul, Dark Caracal, and Check Point research, reinforcing the assessment that the operators were conducting sustained espionage against Venezuelan organizations in sectors such as manufacturing, construction, healthcare, software services, and retail.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
In 2021, ESET detected an ongoing Bandidos campaign and analyzed a newer variant whose Delphi dropper switched from CAST-256 to GOST encryption and reduced its auxiliary DLL set to two modules. The malware retained extensive espionage capabilities, including credential theft, screenshot capture, webcam and audio recording, and USB data theft.
ESET reported that samples labeled as "Full Version" in Check Point's 2020 Bandook report targeted Venezuela and belonged to the Bandidos campaign. This linked previously documented Bandook activity to the broader Bandidos espionage operation.
ESET assessed that the Bandidos cyberespionage campaign had been active since at least 2015, using the Bandook remote access trojan against corporate networks in Spanish-speaking countries. The campaign was primarily focused on Venezuela, which accounted for about 90% of detections.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 69 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.