Bezigate is a backdoor trojan first documented in October 2020 by Proofpoint researchers, attributed to the threat actor TA2541 (also known as TA544 or TA564) with suspected links to Nigerian cybercriminal networks. It falls under the category of Remote Access Trojan (RAT) often used as a delivery mechanism for information stealers such as Agent Tesla, FormBook, and Lokibot.
Bezigate propagates primarily through malicious email campaigns using weaponized Microsoft Word documents or ISO attachments containing VBA macros that download the payload. The trojan establishes C2 communication over HTTP or HTTPS using a victim-ID encoded in request headers, often mimicking legitimate traffic to evade network monitoring. For persistence, it creates a scheduled task or modifies the Windows Registry Run key. Evasion techniques include obfuscated PowerShell scripts, dynamic API resolution, and checking for sandbox or debugger environments before executing. It can perform file enumeration, keylogging, credential harvesting from browsers and email clients, and download additional payloads via a modular architecture.
Bezigate first appeared in October 2020 and saw significant activity in 2021 targeting aviation, aerospace, defense, and manufacturing sectors worldwide. In April 2021, Proofpoint reported a wave of over 5,000 malicious emails delivering Bezigate to hundreds of organizations; no high-profile victim names have been publicly disclosed. No specific CVEs are associated with Bezigate, as it relies on exploited user interaction via macro-based documents. Law enforcement actions have not been documented against this specific malware.
Known file hashes for Bezigate samples include MD5: 3e6c5a7b8c9d0e1f2a3b4c5d6e7f8a9b (example only; real IOCs are available in Proofpoint and ThreatConnect reports). Behavioral signatures include execution of VBScript or PowerShell from Office applications and outbound HTTP requests to IP addresses in the 185.xxx.xxx.xxx range. Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with names like "WindowsUpdate" or "SystemHelper" are common persistence indicators.
Bezigate poses high risk due to its ability to exfiltrate sensitive data—including login credentials, intellectual property, and financial information—and its role as a dropper for more destructive malware. Affected sectors include aerospace, defense, manufacturing, and transportation, with potential financial losses from data breach remediation and operational disruption.
Organizations should implement macro security policies to disable Office macros from untrusted sources, deploy email filtering with attachment scanning, and use endpoint detection and response (EDR) tools with behavioral rules for PowerShell and scheduled task creation. MITRE ATT&CK IDs applicable include T1059 (Command and Scripting Interpreter), T1055 (Process Injection), and T1547 (Boot or Logon Autostart Execution).
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.