logo

Dark_Caracal__2020__Bandook_Signed_Delivered_-_Check_Point_Research.pdf

ID: 7d3939e3-bce2-4c61-9276-4754d5c76413

STIX ID: report--7d3939e3-bce2-4c61-9276-4754d5c76413

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2020-11-30

Last Modified Date: 2020-11-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point Research observed a renewed global campaign using a 13-year-old RAT called Bandook delivered via malicious Word documents that load external templates, drop and execute PowerShell loaders which assemble a Bandook loader from files hosted on cloud services; the loader performs process hollowing into Internet Explorer and communicates with AES-encrypted C2s. The report analyzes signed and unsigned variants (including Certum-signed samples), catalogs commands, TTPs and IoCs (domains, file hashes), notes targeting across government, finance, energy, healthcare and other sectors in multiple countries, and ties the infrastructure to past Dark Caracal/Operation Manul activity.