#bandook — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bandook, aggregated by home.social.
-
Dark Caracal Reloaded: New Malware, Same Hunting Grounds
During a targeted intrusion investigation in June 2026, investigators uncovered GoCaracal, a previously undocumented modular framework written in Go. This sophisticated toolkit exists in two operational profiles: a lightweight implant for establishing access and delivering payloads, and an extended build for sustained intelligence collection with capabilities including keylogging, browser credential theft, WebRTC remote desktop, and SOCKS5 proxying. Analysis of 249 samples traced the framework's evolution from January to July 2026, revealing active development and maturation. A notable innovation includes an Ethereum smart-contract fallback mechanism enabling operators to update C2 infrastructure without redeploying malware. The activity targeted a Venezuelan communications organization using Spanish-language financial lures, weaponized SVG files, and delivery methods consistent with established tradecraft. GoCaracal was deployed alongside an updated Bandook variant, suggesting the new framework currently ...
Pulse ID: 6a8f1fe07f5ffb26e71db532
Pulse Link: https://otx.alienvault.com/pulse/6a8f1fe07f5ffb26e71db532
Pulse Author: AlienVault
Created: 2026-08-26 17:18:24Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bandook #Browser #CyberSecurity #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #SVG #bot #socks5 #AlienVault
-
Poco RAT в лапах дикой кошки: эволюция инструментов хакерской группировки Dark Caracal
В первом квартале 2024 года в поле зрения сотрудников департамента Threat Intelligence экспертного центра безопасности Positive Technologies (PT ESC) попал вредоносный семпл. Сообщество назвало его Poco RAT — по наименованию используемых библиотек POCO для C++. На момент обнаружения семпл не был атрибутирован к какой-либо известной группировке. Исследование семпла выявило определенный набор функций для удаленного управления устройством жертвы, включая загрузку файлов, снятие скриншотов, выполнение команд, управление процессами и файлами. Дополнительный анализ техник, тактик и процедур, цепочки атак и географии кампании позволил связать активность с группировкой Dark Caracal, известной использованием вредоносного ПО Bandook.
https://habr.com/ru/companies/pt/articles/886500/
#Poco_RAT #rat #троян #кибератаки #латам #латинская_америка #дропперы #фишинг #bandook #вредоносное_программное_обеспечение
-
This brand new type of #malware is out to target #Windows machines, so watch out
https://www.techradar.com/pro/security/this-brand-new-type-of-malware-is-out-to-target-windows-machines-so-watch-out
#Bandook is back with a vengeance -
The adaptability of Bandook has been a key factor in its longevity. It has evolved into a polymorphic malware strain, constantly changing its code and obfuscating its presence to evade detection.
-
Кибершпионы атаковали десятки отраслей новым вариантом бэкдора Bandook #Bandook https://www.securitylab.ru/news/514421.php https://twitter.com/SecurityLabnews/status/1333321133576384515/photo/1