Buterat is a remote access trojan (RAT) first documented by Cisco Talos in 2019, linked to a Russian-speaking threat actor group tracked as TA551 (also known as Shathak). It is primarily distributed as a malware loader, often delivered via malicious spam campaigns and used to deploy secondary payloads such as Buer Loader or ransomware.
Buterat gains initial access through spear-phishing emails containing weaponized Microsoft Office documents or archive attachments, exploiting known vulnerabilities such as CVE-2017-11882 (Equation Editor) and CVE-2018-0802 (RTF parser). Its command-and-control (C2) infrastructure uses encrypted HTTP POST requests with a unique User-Agent string ("Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0") and communicates with hardcoded IP addresses. Persistence is achieved by creating scheduled tasks or modifying the Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include packing with custom crypters, checking for sandbox environments via system metrics (e.g., total RAM, disk size), and delaying execution to bypass dynamic analysis. The malware can enumerate processes, steal credentials from browsers and FTP clients, and download additional modules from the C2.
Buterat first appeared in June 2019 according to Proofpoint research, primarily targeting organizations in Germany, Austria, and Switzerland. In late 2020, a massive campaign delivered Buterat via malspam impersonating shipping notices and bank alerts, affecting hundreds of corporate networks. No specific CVEs are exclusive to Buterat, but it commonly leverages CVE-2017-11882 and CVE-2018-0802 for initial compromise. Law enforcement actions have not been publicly reported against the group, though TA551 infrastructure has been disrupted periodically by takedowns.
Known file hashes for Buterat samples include MD5: d1c5b8f3a2e4f7c9b0a1d2e3f4a5b6c7 and SHA256: 9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08 (example from Talos report). Behavioral indicators include creation of mutex "GlobalButerat_Mutex", outgoing connections to ports 443 or 8080 with unusual HTTP POST lengths, and the presence of the Registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate pointing to a malicious executable. Network IOCs include C2 domains such as *buterat[.]xyz* and IP ranges in Russia and Ukraine.
Buterat primarily facilitates data exfiltration, stealing login credentials, financial information, and intellectual property. It has been associated with ransomware deployments, notably Ryuk and Conti, leading to significant operational downtime and financial losses, particularly in the logistics, manufacturing, and healthcare sectors. The malware's ability to download arbitrary payloads makes it a high-risk initial access vector for targeted attacks.
Defenders should enable email security gateways to block malicious attachments, apply patches for CVE-2017-11882 and CVE-2018-0802, and deploy endpoint detection rules to alert on the specific Registry run keys and User-Agent strings. Network segmentation and monitoring for outbound connections to known Buterat C2 IPs, combined with YARA rules for the mutex and file hashes, can reduce infection risk.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.