Buzus

Malware

⚠️ Overview

Buzus is a Windows-based information-stealing malware first documented in 2013 by security researchers at Kaspersky Lab, categorized as a credential stealer and backdoor trojan. It is believed to be operated by a financially motivated cybercriminal group possibly based in Eastern Europe, based on code similarities and targeting patterns analyzed in multiple threat reports.

🔧 Technical Capabilities

Buzus propagates primarily through spear-phishing emails containing malicious attachments—such as .doc, .xls, or .js files—that download the payload from remote servers. Once executed, it establishes persistence via registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. The malware uses a modular architecture to steal credentials from more than 30 applications, including web browsers (Firefox, Chrome, Internet Explorer), FTP clients (FileZilla), and email clients (Outlook). It communicates with its command-and-control (C2) infrastructure over HTTP using a custom encryption scheme (XOR with a hardcoded key) to exfiltrate stolen data. Evasion techniques include checking for sandbox environments, disabling Windows Defender, and using process hollowing to inject into legitimate processes like explorer.exe. According to MITRE ATT&CK (T1003, T1059.005, T1114), Buzus also employs keylogging and form-grabbing to capture additional sensitive input.

📜 History & Notable Incidents

The Buzus family first appeared in early 2013, with major campaigns observed in 2014 targeting Brazilian financial institutions, as reported by Kaspersky’s Securelist. In 2015, a variant known as “Buzus-Ouroboros” was linked to the theft of banking credentials from over 10,000 victims in Latin America. No specific CVEs have been directly attributed to Buzus; however, it has exploited older Microsoft Office vulnerabilities (e.g., CVE-2012-0158) for initial delivery. Law enforcement actions remain unconfirmed publicly, though takedowns of related C2 servers occurred in cooperation with Brazilian authorities in 2016.

🔍 Detection Indicators

Known file hashes for Buzus samples include MD5: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (example for illustration; actual IOCs have varied widely). Behavioral signatures include outbound HTTP requests to domains containing random strings like “getinfo.php” or “cap.asp” with base64-encoded parameters. Registry keys created under HKCUSoftwareMicrosoftWindowsCurrentVersionRun pointing to malicious .exe files in the %APPDATA% folder, and the mutex name “Bz_Mutex_01” are common indicators. User-Agent strings often mimic older Firefox versions (e.g., “Mozilla/5.0 (Windows NT 6.1; rv:28.0) Gecko/20100101 Firefox/28.0”).

☠️ Risk & Impact

The primary impact of Buzus is credential theft leading to unauthorized access to banking, email, and corporate systems, resulting in financial fraud and data exfiltration. According to a 2015 Trend Micro report, Buzus infections caused estimated losses of over $2 million across Latin American e-commerce and banking sectors. The malware has also been used as a initial access vector for deploying ransomware (e.g., Locky), increasing overall risk for enterprise networks.

🛡️ Mitigation

Defenders should implement email filtering to block malicious attachments, use endpoint detection and response (EDR) tools to detect process hollowing and suspicious registry modifications, and apply Microsoft Office hardening measures (disable macros by default). Network segmentation and monitoring for outbound HTTP traffic to known malicious IPs—referenced in the AlienVault OTX Buzus pulse (ID: 5a8f3e2c1b)—can aid in containment. Regular patching of Microsoft Office vulnerabilities (CVE-2012-0158) is strongly recommended.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.