logo

Roaming_Tiger__2016__PaloAlto_BBSRAT-Attacks-Targeting-Russian-Organizations-Linked-to-Roaming-Tiger_Dec-22-15.pdf

ID: 1c1f2628-c70b-4a84-b977-77d0d1ff03a2

STIX ID: report--1c1f2628-c70b-4a84-b977-77d0d1ff03a2

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2016-04-04

Last Modified Date: 2016-04-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Unit 42 report analyzes BBSRAT, a remote access Trojan used in the Roaming Tiger espionage campaign targeting Russian organizations, detailing spear-phishing delivery, two deployment methods (CAB dropper with DLL sideloading and a PowerSploit-based downloader), process-hollowing and reflective injection execution, persistence via registry/COM, C2 protocol and commands, IOCs (hashes and domains) and a YARA detection rule.