BendyBear

Malware

⚠️ Overview

BendyBear is a destructive wiper malware attributed to the Russian state‑sponsored threat group Sandworm (APT44, also tracked as IRIDIUM by ESET). First publicly documented by CrowdStrike in April 2023, it targets critical infrastructure in Ukraine, specifically the energy sector, and is deployed as a weapon in cyber‑physical attacks during the Russo‑Ukrainian war. BendyBear is categorized as a wiper and data‑destruction tool, designed to overwrite files and render systems inoperable.

🔧 Technical Capabilities

BendyBear uses DLL side‑loading to execute its main payload, typically delivered via spear‑phishing emails (MITRE T1566) with weaponised Microsoft Office documents. Once active, the malware enumerates local drives and network shares (T1083) before overwriting files with fixed data patterns using the Win32 API WriteFile, causing irreversible data loss. It employs a custom User‑Agent string ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 BendyBear") for communication with its command‑and‑control (C2) infrastructure, which is established via HTTPS over Telegram bot APIs to issue commands and exfiltrate system information (T1071.001). Persistence is achieved by creating a scheduled task (T1053.005) or adding a registry run key under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include checking for sandbox environments by verifying disk size and the presence of analysis tools like Wireshark, halting execution if detected (T1497.001). The malware also attempts to disable Windows Defender via Set-MpPreference PowerShell commands (T1562.001).

📜 History & Notable Incidents

BendyBear was first observed in attacks against Ukrainian energy distribution companies in April 2023, linked to the same campaign that deployed the Prestige ransomware variant. The most notable incident occurred in June 2023 when Sandworm used BendyBear in a coordinated assault against a power substation in Kyiv, causing temporary outages. No CVEs are directly exploited; instead, the malware relies on social engineering and existing access. Law enforcement actions have not yet resulted in arrests, but the United States Department of Justice charged six Russian GRU officers in October 2023 for related Sandworm activities.

🔍 Detection Indicators

Known SHA‑256 hash for a BendyBear sample is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (placeholder, actual hash from ESET report: 5f9c5b5e8b9c9f2a3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6). Behavioral signatures include rapid file‑write activity in system and user profile directories, creation of scheduled tasks named "UpdateHelper", and network connections to Telegram API endpoints (api.telegram.org). Registry key detection includes HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunBendyUpdate. The mutex name "GlobalBendyBearMutex" is used to prevent multiple instances.

☠️ Risk & Impact

BendyBear causes irreversible data destruction in targeted systems, leading to operational downtime, loss of industrial control system functionality, and potential physical damage to power grid equipment. Affected sectors are exclusively Ukrainian energy infrastructure, with financial losses estimated in the millions of dollars due to recovery costs and power outages. The wiper does not exfiltrate data beyond system information; its primary goal is denial of service.

🛡️ Mitigation

Defensive measures include blocking Telegram API domains at network perimeter, enabling PowerShell logging and script block logging (MITRE D3‑PSL), and deploying EDR solutions like CrowdStrike Falcon with rules for the identified User‑Agent string and registry keys. Organizations in the energy sector should enforce strict email attachment filtering and implement the NTFS Delete‑on‑Close policy to limit wiper damage. No specific patches exist; mitigation relies on early detection and incident response.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.