Dark_Caracal__2020__Bandook_Signed_Delivered_-_Check_Point_Research.pdf
ID: 7d3939e3-bce2-4c61-9276-4754d5c76413
STIX ID: report--7d3939e3-bce2-4c61-9276-4754d5c76413
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2020-11-30
Last Modified Date: 2020-11-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Check Point Research observed a renewed global campaign using a 13-year-old RAT called Bandook delivered via malicious Word documents that load external templates, drop and execute PowerShell loaders which assemble a Bandook loader from files hosted on cloud services; the loader performs process hollowing into Internet Explorer and communicates with AES-encrypted C2s. The report analyzes signed and unsigned variants (including Certum-signed samples), catalogs commands, TTPs and IoCs (domains, file hashes), notes targeting across government, finance, energy, healthcare and other sectors in multiple countries, and ties the infrastructure to past Dark Caracal/Operation Manul activity.
