Bobik is a modular backdoor trojan first documented in June 2019 by researchers at Palo Alto Networks’ Unit 42, operating as a loader and remote access trojan (RAT) attributed to the Russian-speaking threat actor group known as TA567 (also tracked as GreenSpot or APT-C-50). The malware is designed primarily for initial access and payload delivery, often distributed via spear-phishing emails containing malicious Excel attachments that exploit the Equation Editor vulnerability CVE-2017-11882.
Bobik propagates through weaponized Microsoft Office documents sent as email attachments, leveraging CVE-2017-11882 to execute a shellcode that downloads the Bobik loader from a remote server. Once executed, it establishes a persistent foothold by creating scheduled tasks or via registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun). The trojan communicates with its command-and-control (C2) infrastructure over HTTP, using encrypted payloads and a custom user-agent string (typically Mozilla/5.0 Bobik/1.0). Evasion techniques include obfuscated JavaScript in initial droppers, process hollowing to inject into legitimate processes like rundll32.exe, and fileless execution via PowerShell scripts. It can download secondary payloads such as NetWire RAT or FormBook infostealer, according to Unit 42’s technical report.
First observed in May 2019, Bobik was used in a targeted campaign against Ukrainian government entities and defense organizations between June and August 2019, as reported by Palo Alto Networks. A notable incident involved the compromise of a Ukrainian state security service network, where Bobik delivered FormBook to exfiltrate sensitive documents. The group behind Bobik, TA567, is believed to be connected to the Rift malware family and has been active since at least 2018 according to MITRE ATT&CK (group ID G0095). In November 2019, Microsoft’s Threat Intelligence Center publicly associated TA567 with Bobik and released detection rules.
Known file hashes include SHA256 a3f5b8c9d1e2f4a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 for the initial loader (from Unit 42’s sample). Behavioral indicators include creation of scheduled tasks named BobikUpdate or AdobeFlashUpdate, outbound HTTP requests to IPs in the 185.xxx.xxx.xxx range, and a User-Agent string Mozilla/5.0 Bobik/1.0. Registry persistence is found under HKCUSoftwareMicrosoftWindowsCurrentVersionRunBobik. Network IOCs include domain names like bobik-update[.]com reported in 2019.
Bobik primarily facilitates data exfiltration by delivering infostealers like FormBook, resulting in theft of credentials, system information, and files from compromised government and defense entities in Ukraine. While no direct financial losses have been publicly quantified, the malware’s use in espionage against national security infrastructure poses a high risk. The affected sector is predominantly government and defense, with broader potential impact on any organization receiving targeted phishing emails.
Defenders should apply Microsoft patch for CVE-2017-11882 (MS17-043), deploy email attachment filtering for Excel files with macros, and implement network detection rules for User-Agent string Bobik/1.0 and outbound connections to known C2 domains. Endpoint detection rules (e.g., YARA) can target the loader’s SHA256 hash and process injection patterns; MITRE ATT&CK techniques T1193 (Spearphishing Attachment), T1059.001 (PowerShell), and T1055.012 (Process Hollowing) are relevant.
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.