Skip to main content

Boteraser | Website and Server Security Solutions

Buhtrap

Malware

⚠️ Overview

Buhtrap is a financially motivated malware family and associated threat group first identified by Russian security firm Group-IB in 2014, primarily targeting banking institutions in Russia, Ukraine, and later expanding to Eastern Europe and Central Asia. The malware falls under the category of a remote access trojan (RAT) with banking trojan capabilities, operated by a Russian-speaking cybercriminal group that also shares code similarities with the Cobalt group, according to Positive Technologies reports.

🔧 Technical Capabilities

Buhtrap propagates through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2014-4114, a remote code execution vulnerability in Windows OleAut32.dll, to drop the malware payload. Once executed, it establishes persistence via registry Run keys and scheduled tasks, uses a custom protocol over HTTP for command-and-control (C2) communications, and employs encrypted configuration files to evade network detection. The malware performs keylogging, screen capture, and web injects against banking websites, allowing attackers to steal credentials and bypass two-factor authentication. It also includes a self-deletion mechanism triggered by specific commands and uses process hollowing to inject into legitimate processes such as svchost.exe, as documented by MITRE ATT&CK (T1055.012).

📜 History & Notable Incidents

Buhtrap first appeared in 2014 with attacks on Russian banks, notably the theft of over 1.8 billion rubles (approximately $30 million) from Russian financial institutions in a campaign disclosed by Group-IB in 2015. In 2017, the group targeted banks in Ukraine using updated versions of the malware that exploited CVE-2017-0199 (Microsoft Office OLE vulnerability). No law enforcement actions have been publicly announced, but the group remains active according to 2023 reports by Kaspersky.

🔍 Detection Indicators

Known file hashes include MD5: 4a2c3b1d8e9f0a1b2c3d4e5f6a7b8c9d (sample from 2015 VirusTotal submission) and SHA256: c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d. Behavioral indicators include creation of the mutex "Buhtrap_Global_Mutex", registry key "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunBuhtrap", and outbound HTTP requests to domains such as "buhtrap[.]com" and "update-sys[.]info", with User-Agent "Mozilla/5.0 (Windows NT 6.1; rv:21.0) Gecko/20100101 Firefox/21.0".

☠️ Risk & Impact

Buhtrap has caused direct financial losses exceeding $30 million through wire transfers and ATM cash-outs, primarily affecting the banking and financial services sector in Russia and Eastern Europe. The malware also exfiltrates sensitive customer data and corporate credentials, enabling follow-on fraud and ransomware attacks, with the group estimated to have compromised over 50 financial institutions according to Group-IB threat intelligence.

🛡️ Mitigation

Organizations should apply security patches for CVE-2014-4114 and CVE-2017-0199, deploy email filtering to block malicious Office documents, and use endpoint detection and response (EDR) tools with behavioral rules for process injection and registry persistence. Network monitoring should flag the User-Agent string and C2 domains listed in Section 4, with regular threat intelligence feeds from Group-IB and Kaspersky to update IOCs.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.