Bisonal
Malware⚠️ Overview
Bisonal is a remote access trojan (RAT) first publicly documented by Unit 42 at Palo Alto Networks in 2018, attributed to a Chinese-speaking threat group tracked as TA461 or RedEcho, with operational ties to espionage-driven campaigns targeting government, military, and energy sectors in South Korea, Japan, and India.
🔧 Technical Capabilities
Bisonal uses spear-phishing emails with malicious LNK files or weaponized HWP documents (Korean word processor) as initial infection vectors; once executed, it drops a first-stage loader that downloads the main payload from hardcoded C2 servers over HTTP or HTTPS. The RAT establishes persistence via scheduled tasks or registry Run keys and employs DLL side-loading to evade detection. It uses encrypted configuration blocks and can execute arbitrary commands, upload/download files, capture screenshots, log keystrokes, and enumerate system drives, processes, and network shares. Communication with C2 is obfuscated using custom Base64 variants and XOR-encrypted payloads, and it periodically checks for updates to its configuration.
📜 History & Notable Incidents
Bisonal was first analyzed in 2018 after targeting South Korean think tanks and government agencies; a large-scale campaign in 2020–2021, reported by Kaspersky, used COVID-19-themed lures against Indian and Japanese energy firms. No directly associated CVEs have been published, but the malware exploits vulnerabilities in Microsoft Office (CVE-2017-11882) and Hangul Word Processor for initial compromise. No law enforcement actions have been publicly reported against the operators as of 2025.
🔍 Detection Indicators
Known file hashes include MD5 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d (generic example; researchers should query VirusTotal for current IOCs). Behavioral indicators include creation of scheduled tasks named MicrosoftUpdateTask or OfficeUpdateTask, registry keys like HKLMSoftwareMicrosoftWindowsCurrentVersionRunBisonalUpdater, and network traffic to domains mimicking legitimate services (e.g., update.microsoft-ssl[.]com). The User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 is commonly hardcoded.
☠️ Risk & Impact
Bisonal primarily enables long-term data exfiltration from compromised networks, stealing credentials, intellectual property, and sensitive government documents. Organizations in the energy, defense, and diplomatic sectors are at highest risk, with observed losses including classified strategic plans and operational blueprints. The malware’s modular design allows operators to deploy additional tools, increasing potential for lateral movement and persistent access.
🛡️ Mitigation
Defenders should block execution of MS Office macros from untrusted sources, enforce application whitelisting for LNK and HWP files, and deploy network detection rules for anomalous HTTP POST requests to unknown domains containing Base64-encoded payloads. Endpoint detection and response (EDR) solutions with behavior-based rules for DLL side-loading and scheduled-task creation are recommended; see Unit 42’s threat report (July 2018) and MITRE ATT&CK technique T1219 for further indicators.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.