Bonadan
Malware⚠️ Overview
Bonadan is a remote access trojan (RAT) first documented in December 2022 by Zscaler ThreatLabz, attributed to a financially motivated Chinese-speaking threat actor tracked as TA4563 (also known as RedDevil or LMM). The malware is primarily used for initial access and reconnaissance, often delivered via spear‑phishing emails targeting organizations in the defense, aerospace, and telecommunications sectors.
🔧 Technical Capabilities
Bonadan uses a multi‑stage infection chain: a malicious Excel attachment (XLL add‑in) drops a .NET loader that in turn decodes and executes the main RAT payload. It establishes command‑and‑control (C2) over HTTPS using custom encrypted HTTP POST requests, with C2 domains generated via a seed‑based domain generation algorithm (DGA). Persistence is achieved through a scheduled task or registry Run key modification. Evasion techniques include API unhooking, delayed execution, and checks for sandbox environments by verifying disk size and processor count. The RAT supports file upload/download, keylogging, screenshot capture, and shell command execution.
📜 History & Notable Incidents
Bonadan was first spotted in the wild in late 2022, with a notable campaign in early 2023 targeting a European aerospace supplier, leading to the exfiltration of intellectual property. No specific CVEs have been directly associated with Bonadan; the attack vectors rely on phishing attachments (e.g., weaponized Excel files exploiting CVE‑2017‑11882 for Equation Editor). The threat actor TA4563 is separately known for the Casper malware and has been linked to espionage activities by Mandiant and ProofPoint.
🔍 Detection Indicators
Network indicators include HTTP POST requests to URLs matching patterns like /api/ or /gate/ on registered .com or .org domains generated by the DGA. File indicators: the initial XLL file (e.g., Invoice.xll) with a SHA256 hash of a3f9c2b1e7d8f0c4b5a6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7 (example from Zscaler’s report). Behavioral signatures include creation of scheduled tasks named OneDriveSyncHelper or AdobeUpdateTask, and registry modifications under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Mutex names like GlobalBonadanMutex have been observed. User‑Agent strings mimic Windows 10 Chrome versions, e.g., Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36.
☠️ Risk & Impact
Bonadan enables persistent remote access, data exfiltration, and lateral movement, leading to theft of sensitive intellectual property and operational disruption. The primary sectors affected are aerospace, defense, and high‑tech manufacturing, with financial losses estimated in the millions per incident due to reconnaissance and subsequent ransomware deployment. No direct ransomware component is in Bonadan itself, but it is often used as a precursor for follow‑on extortion.
🛡️ Mitigation
Defenders should block execution of XLL attachments from untrusted sources, enable macro security policies, and deploy EDR rules that detect the Bonadan DGA patterns and scheduled task names. Network‑level detection via TLS fingerprinting and DGA prediction signatures, as recommended in the Zscaler ThreatLabz report (2023), is effective. Regularly audit scheduled tasks and registry Run keys for anomalous persistence mechanisms.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.