Roaming_Tiger__2016__PaloAlto_BBSRAT-Attacks-Targeting-Russian-Organizations-Linked-to-Roaming-Tiger_Dec-22-15.pdf
ID: 1c1f2628-c70b-4a84-b977-77d0d1ff03a2
STIX ID: report--1c1f2628-c70b-4a84-b977-77d0d1ff03a2
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2016-04-04
Last Modified Date: 2016-04-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Unit 42 report analyzes BBSRAT, a remote access Trojan used in the Roaming Tiger espionage campaign targeting Russian organizations, detailing spear-phishing delivery, two deployment methods (CAB dropper with DLL sideloading and a PowerSploit-based downloader), process-hollowing and reflective injection execution, persistence via registry/COM, C2 protocol and commands, IOCs (hashes and domains) and a YARA detection rule.
