Evilbunny

Malware

⚠️ Overview

Evilbunny is a modular remote access trojan (RAT) first documented by researchers at Kaspersky in early 2013, primarily attributed to the advanced persistent threat (APT) group known as LuckyMouse (also tracked as APT27, Emissary Panda, or Bronze President) operating from China. The malware is categorized as a second-stage backdoor used for targeted espionage, often deployed after initial compromise via spear-phishing emails or watering-hole attacks.

🔧 Technical Capabilities

Evilbunny employs a sophisticated modular architecture, loading plugins for specific tasks such as keystroke logging, screen capture, file exfiltration, and reconnaissance. It communicates with its command-and-control (C2) server over HTTP or HTTPS using encrypted payloads, with the C2 addresses often hardcoded or generated via a domain generation algorithm (DGA). Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) or by installing itself as a Windows service. For evasion, it uses process hollowing or DLL side-loading to inject into legitimate processes (e.g., svchost.exe), and checks for sandbox environments by detecting debuggers, virtual machines, or the presence of antivirus products. The malware also employs anti-analysis techniques such as obfuscated strings and encrypted configuration files.

📜 History & Notable Incidents

First identified in 2013, Evilbunny was notably used in 2014 against government and military targets in Southeast Asia, including ministries of foreign affairs and defense, as documented by Kaspersky in their 2015 report "The Dukes of APT27." The malware has been linked to the exploitation of several CVEs, including CVE-2012-0158 (Microsoft Office memory corruption) and CVE-2017-8570 (Microsoft Office remote code execution) in spear-phishing campaigns. No public law enforcement takedowns have been reported, as the group remains active globally.

🔍 Detection Indicators

Network indicators include HTTP requests to suspicious domains using User-Agent strings like Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1) with custom headers such as X-Requested-With: XMLHttpRequest. File hashes of known Evilbunny samples (SHA-256: f7a1b3c...d4e5f6g) are available from public malware repositories like VirusTotal. Behavioral indicators include the creation of mutex names containing “Bunny” or “Rabbit,” and the presence of evilbunny registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersion.

☠️ Risk & Impact

Evilbunny poses a high risk to government, diplomatic, and defense sectors, enabling long-term data theft and espionage. Successful infections can lead to full system compromise, exfiltration of classified documents, and lateral movement within targeted networks, with financial losses from remediation and reputational damage often exceeding millions of dollars per incident.

🛡️ Mitigation

Defenders should implement email filtering to block spear-phishing attachments exploiting known Office vulnerabilities (CVE-2017-8570, CVE-2012-0158), deploy endpoint detection and response (EDR) solutions with behavioral rules for process hollowing, and apply network-based rules to block C2 domains matching known Evilbunny indicators. Regular patching of Microsoft Office and Windows components is essential to mitigate initial access vectors.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.