logo

BBSRAT Attacks Targeting Russian Organizations Linked to Roaming Tiger - Palo Alto Networks BlogPalo Alto Networks Blog

ID: 53790f90-e8d8-42eb-a311-9e39208d5d8f

STIX ID: report--53790f90-e8d8-42eb-a311-9e39208d5d8f

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2015-12-24

Last Modified Date: 2015-12-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Executive summary: Unit 42 describes BBSRAT, a custom RAT tied to the Roaming Tiger activity that targeted Russian organisations via spear-phishing and weaponized Office docs (CVE-2012-0158). The report documents two deployment methods (CAB sideloading with a malicious DLL and a PowerSploit-based downloader), persistence and process-injection behaviors, the C2 protocol and commands, YARA detection, and a comprehensive set of IOCs (file hashes, domains, IPs) and mitigation recommendations.