logo

BuhTrap__2019__Buhtrap_group_uses_zero_day_in_latest_espionage_campaigns.pdf

ID: 7c622484-4110-490b-8fc9-c58822017868

STIX ID: report--7c622484-4110-490b-8fc9-c58822017868

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2019-07-11

Last Modified Date: 2019-07-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET details how the Buhtrap crime group shifted from targeting Russian businesses and banks to espionage against governmental organizations (2015–2019), including use of a Windows local privilege escalation zero‑day (CVE‑2019‑1132), NSIS droppers, side‑loading of signed binaries, a password‑stealer module, and Meterpreter using DNS tunneling; the report provides technical analysis, IoCs (SHA‑1s, C2 domains, certificates) and MITRE ATT&CK mappings.