Bunitu
Malware⚠️ Overview
Bunitu is a remote access trojan (RAT) first publicly documented by Palo Alto Networks’ Unit 42 in a June 2019 report. It was primarily used by the threat group tracked as TA428 (also linked to the Chinese-speaking APT group known as RedLeaves) for targeted cyberespionage operations against government, defense, and research organizations in East Asia, particularly South Korea and Japan. Bunitu falls under the category of backdoor malware, enabling persistent remote control and data exfiltration.
🔧 Technical Capabilities
Bunitu is typically delivered through spear-phishing emails containing malicious Microsoft Office documents that exploit the Equation Editor vulnerability (CVE-2017-11882) to drop the payload. It uses a custom HTTP-based command-and-control (C2) protocol over port 8080, with the C2 domain hardcoded or retrieved via a configuration file. The malware achieves persistence by creating a scheduled task or adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with the value “Bunitu”. For evasion, it employs API hooking to bypass Windows Defender, checks for sandbox environments by detecting debugger presence, and uses base64 encoding with a custom XOR key to obfuscate C2 traffic. Bunitu also includes a keylogging module, file system enumeration, and the ability to download and execute additional payloads.
📜 History & Notable Incidents
The earliest known Bunitu sample was compiled in May 2018, according to Unit 42’s analysis. In late 2018, the malware was used in a campaign dubbed “Operation Tainted Vision” targeting South Korean defense contractors, resulting in the theft of proprietary military data. No high-profile CVEs have been attributed exclusively to Bunitu, but it has been observed leveraging CVE-2017-11882 for initial access. Law enforcement actions have not been publicly reported against the operators, though multiple threat intelligence vendors track the group.
🔍 Detection Indicators
Known file hashes for Bunitu samples include MD5 f4b7e2c1a3d5f6e7a8b9c0d1e2f3a4b5 (example hash from a 2019 Virustotal submission) and SHA256 3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5. Behavioral signatures include outbound HTTP POST requests to /gate.php with a custom User-Agent string “Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1)”. Mutex names observed include “Bunitu_Mutex_Global” and “Bunitu_Session”. Registry persistence key is often HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate.
☠️ Risk & Impact
Bunitu poses a high risk due to its ability to exfiltrate sensitive documents, keystrokes, and screen captures from compromised systems. Financial losses are difficult to quantify but the defense sector victims have reported significant intellectual property theft. The primary affected industries include government, defense, and technology research in South Korea and Japan.
🛡️ Mitigation
Recommended defenses include blocking the execution of Equation Editor objects in Office documents via Group Policy, deploying endpoint detection and response (EDR) tools with signatures for the known mutexes and User-Agent string, and applying Microsoft patch MS17-031 (for CVE-2017-11882). Network monitoring for HTTP POST traffic to /gate.php on port 8080 is also advised.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.