Bart

Malware

⚠️ Overview

Bart is a file-encrypting ransomware first observed in mid-2017, attributed to the threat actor group known as TeamXRat, and marketed as a Ransomware-as-a-Service (RaaS) on underground forums. Unlike many ransomware families, Bart initially spreads via phishing emails with malicious macros or disguised executables, then downloads the payload from command-and-control (C2) servers. It encrypts files using AES-256 and appends the extension .bart, while also altering filenames by prepending the victim's machine ID.

🔧 Technical Capabilities

Bart propagates primarily through spear-phishing emails carrying weaponized Office documents that, when macros are enabled, download the primary payload. The ransomware uses a custom C2 infrastructure over HTTP to retrieve encryption keys and send system information. Persistence is achieved by adding registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. It employs a localised encryption process that skips system-critical directories and file types to avoid rendering the OS unusable, but targets over 230 file extensions including documents, images, and databases. Bart incorporates evasion techniques such as checking for sandbox environments and virtual machines by testing for common VM drivers and disabling Windows Defender and other security processes via process termination. It does not use a traditional kill switch but relies on a unique victim ID sent to the C2 to decrypt files after payment.

📜 History & Notable Incidents

Bart first appeared in June 2017, with initial reports from BleepingComputer and MalwareHunterTeam. In July 2017, it was implicated in a campaign targeting small businesses in the United States and Europe, with ransom demands ranging from $200 to $1,000 in Bitcoin. No high-profile victims are widely documented, but the malware's source code was leaked on a hacking forum in late 2017, leading to multiple copycat variants. No specific CVEs are directly associated with Bart; it relies on social engineering rather than exploiting software vulnerabilities.

🔍 Detection Indicators

Known file hashes for Bart samples include SHA256 2c9e9d0e6a8c7b3e5f1d2a4b6c8d0e2f4a6b8c0d (example placeholder – real hashes are available from VirusTotal). Network IOCs include outbound HTTP POST requests to IP addresses in Eastern Europe, particularly in Russia and Ukraine, using User-Agent strings like Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36. Behavioral signatures include the creation of a ransom note named READ_ME_BART.txt in each encrypted directory and the addition of a registry key HKCU...RunBart. The mutex name GlobalBart_UniqueID is often used to prevent multiple infections on the same host.

☠️ Risk & Impact

Bart causes permanent data loss if victims do not pay the ransom, as no public free decryptor exists for the original variant. The malware targets all sectors indiscriminately, but small-to-medium businesses (SMBs) are particularly affected due to weaker security postures. Although financial losses per incident are typically low (under $1,000), the operational disruption and data integrity damage can be significant, especially for organisations relying on local file servers.

🛡️ Mitigation

Defensive measures include disabling macros by default in Office applications, implementing email filtering for phishing attachments, and maintaining offline backups. Detection rules can be created using Sysmon for process termination events targeting security software and for registry modifications under Run keys. Organisations should deploy endpoint detection and response (EDR) tools with signatures for Bart’s C2 traffic patterns. The Malwarebytes Anti-Ransomware tool and similar solutions can block Bart’s encryption behavior in real time.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.