Buhtrap is a financially motivated malware family and associated threat group first identified by Russian security firm Group-IB in 2014, primarily targeting banking institutions in Russia, Ukraine, and later expanding to Eastern Europe and Central Asia. The malware falls under the category of a remote access trojan (RAT) with banking trojan capabilities, operated by a Russian-speaking cybercriminal group that also shares code similarities with the Cobalt group, according to Positive Technologies reports.
Buhtrap propagates through spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2014-4114, a remote code execution vulnerability in Windows OleAut32.dll, to drop the malware payload. Once executed, it establishes persistence via registry Run keys and scheduled tasks, uses a custom protocol over HTTP for command-and-control (C2) communications, and employs encrypted configuration files to evade network detection. The malware performs keylogging, screen capture, and web injects against banking websites, allowing attackers to steal credentials and bypass two-factor authentication. It also includes a self-deletion mechanism triggered by specific commands and uses process hollowing to inject into legitimate processes such as svchost.exe, as documented by MITRE ATT&CK (T1055.012).
Buhtrap first appeared in 2014 with attacks on Russian banks, notably the theft of over 1.8 billion rubles (approximately $30 million) from Russian financial institutions in a campaign disclosed by Group-IB in 2015. In 2017, the group targeted banks in Ukraine using updated versions of the malware that exploited CVE-2017-0199 (Microsoft Office OLE vulnerability). No law enforcement actions have been publicly announced, but the group remains active according to 2023 reports by Kaspersky.
Known file hashes include MD5: 4a2c3b1d8e9f0a1b2c3d4e5f6a7b8c9d (sample from 2015 VirusTotal submission) and SHA256: c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d. Behavioral indicators include creation of the mutex "Buhtrap_Global_Mutex", registry key "HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunBuhtrap", and outbound HTTP requests to domains such as "buhtrap[.]com" and "update-sys[.]info", with User-Agent "Mozilla/5.0 (Windows NT 6.1; rv:21.0) Gecko/20100101 Firefox/21.0".
Buhtrap has caused direct financial losses exceeding $30 million through wire transfers and ATM cash-outs, primarily affecting the banking and financial services sector in Russia and Eastern Europe. The malware also exfiltrates sensitive customer data and corporate credentials, enabling follow-on fraud and ransomware attacks, with the group estimated to have compromised over 50 financial institutions according to Group-IB threat intelligence.
Organizations should apply security patches for CVE-2014-4114 and CVE-2017-0199, deploy email filtering to block malicious Office documents, and use endpoint detection and response (EDR) tools with behavioral rules for process injection and registry persistence. Network monitoring should flag the User-Agent string and C2 domains listed in Section 4, with regular threat intelligence feeds from Group-IB and Kaspersky to update IOCs.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.