Bezigate
Malware⚠️ Overview
Bezigate is a backdoor trojan first documented in October 2020 by Proofpoint researchers, attributed to the threat actor TA2541 (also known as TA544 or TA564) with suspected links to Nigerian cybercriminal networks. It falls under the category of Remote Access Trojan (RAT) often used as a delivery mechanism for information stealers such as Agent Tesla, FormBook, and Lokibot.
🔧 Technical Capabilities
Bezigate propagates primarily through malicious email campaigns using weaponized Microsoft Word documents or ISO attachments containing VBA macros that download the payload. The trojan establishes C2 communication over HTTP or HTTPS using a victim-ID encoded in request headers, often mimicking legitimate traffic to evade network monitoring. For persistence, it creates a scheduled task or modifies the Windows Registry Run key. Evasion techniques include obfuscated PowerShell scripts, dynamic API resolution, and checking for sandbox or debugger environments before executing. It can perform file enumeration, keylogging, credential harvesting from browsers and email clients, and download additional payloads via a modular architecture.
📜 History & Notable Incidents
Bezigate first appeared in October 2020 and saw significant activity in 2021 targeting aviation, aerospace, defense, and manufacturing sectors worldwide. In April 2021, Proofpoint reported a wave of over 5,000 malicious emails delivering Bezigate to hundreds of organizations; no high-profile victim names have been publicly disclosed. No specific CVEs are associated with Bezigate, as it relies on exploited user interaction via macro-based documents. Law enforcement actions have not been documented against this specific malware.
🔍 Detection Indicators
Known file hashes for Bezigate samples include MD5: 3e6c5a7b8c9d0e1f2a3b4c5d6e7f8a9b (example only; real IOCs are available in Proofpoint and ThreatConnect reports). Behavioral signatures include execution of VBScript or PowerShell from Office applications and outbound HTTP requests to IP addresses in the 185.xxx.xxx.xxx range. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like "WindowsUpdate" or "SystemHelper" are common persistence indicators.
☠️ Risk & Impact
Bezigate poses high risk due to its ability to exfiltrate sensitive data—including login credentials, intellectual property, and financial information—and its role as a dropper for more destructive malware. Affected sectors include aerospace, defense, manufacturing, and transportation, with potential financial losses from data breach remediation and operational disruption.
🛡️ Mitigation
Organizations should implement macro security policies to disable Office macros from untrusted sources, deploy email filtering with attachment scanning, and use endpoint detection and response (EDR) tools with behavioral rules for PowerShell and scheduled task creation. MITRE ATT&CK IDs applicable include T1059 (Command and Scripting Interpreter), T1055 (Process Injection), and T1547 (Boot or Logon Autostart Execution).
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.