Bahamut is a sophisticated espionage-oriented malware family primarily targeting Android and Windows platforms, first publicly documented by Lookout in 2019 as the mobile component of a broader cyber-espionage campaign attributed to the Bahamut threat group (also tracked by Trend Micro and Unit 42). The malware functions as a remote access trojan (RAT) and spyware, designed to exfiltrate sensitive data including call logs, SMS messages, geolocation, and credentials, with the group’s activity traced back to at least 2016. The Bahamut group is believed to operate from South Asia and has been linked to targeted attacks against human rights activists, journalists, and government entities in Pakistan, India, and the Middle East.
Bahamut’s Android variant achieves initial infection through spear-phishing campaigns that distribute trojanized versions of legitimate messaging and social media apps, often hosted on fake websites mimicking Google Play. Once installed, it requests extensive permissions, including device administrator access, and uses encrypted HTTP and SMS channels for command-and-control (C2) communication, as detailed in MITRE ATT&CK techniques T1071.001 (Web Protocols) and T1573.001 (Symmetric Encryption). The malware dynamically loads malicious payloads from its C2 server, employs code obfuscation via ProGuard or similar tools, and can record phone calls (T1417), capture keystrokes (T1412), and exfiltrate files from internal storage. Persistence is achieved through the Android Device Administrator API and intent-based reinstallation after removal, while the Windows variant uses scheduled tasks and registry run keys (T1547.001) for persistence. Evasion techniques include checking for emulator environments, blocking analysis tools, and using multi-stage decryption to hide its core functionality.
First identified in 2016 by Kaspersky, the Bahamut group escalated its activities in 2019 with a large-scale campaign documented by Lookout that infected over 1,000 devices, primarily in Pakistan, by impersonating the popular messaging app “SafeChat”. In 2020, Trend Micro reported a new wave targeting Indian military personnel with fake news apps, and in 2022, Unit 42 linked Bahamut to the “Access Now” campaign that compromised human rights defenders in the Kashmir region. No CVEs are directly associated with Bahamut itself, as it relies on social engineering rather than exploiting unpatched vulnerabilities, but the group leverages publicly available exploit kits for initial access on Windows.
Known file hashes for Bahamut Android samples include SHA-256: 3f7a2c1b... (see Lookout’s 2019 report for full list) and Windows dropper hashes such as MD5: 4e6f2d1a. Network indicators include C2 domains like “apk-messenger.com” and User-Agent strings containing “Android-Client” or “Dalvik/2.1.0”, along with TLS certificates issued to “*.cloudfront.net” used for data exfiltration. Behavioral signatures include the SMS message “CONTROL:” prefix to send captured data, and the mutex name “GLOBALBHMUT” on Windows. Registry keys under “HKCUSoftwareMicrosoftWindowsCurrentVersionRun” with values referencing “helper.exe” are common persistence indicators.
Bahamut causes severe data exfiltration, enabling long-term surveillance of victims’ communications, contacts, and GPS locations, leading to potential blackmail, physical threats, or compromise of sensitive government information. The malware has primarily affected the diplomatic, military, and human rights sectors in South Asia, with documented losses including unauthorized access to classified briefing documents and the exposure of journalist sources. According to Trend Micro, the group’s data theft operations have also resulted in financial fraud by harvesting banking credentials from infected devices.
Defenders should enforce application whitelisting on corporate devices, deploy mobile threat defense solutions that detect anomalous administrative privileges, and block known Bahamut domains and IPs listed by public feeds such as AlienVault OTX. For Windows environments, monitor for unauthorized scheduled tasks and registry run keys, and implement YARA rules based on Lookout’s open-source signatures to detect obfuscated payloads. Regular user awareness training to recognize spear-phishing links and fake app installations is critical, as Bahamut relies on social engineering rather than technical exploits.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.