spyware remote access trojan

ESET uncovers the 'Bandidos' espionage campaign using the Bandook RAT against corporate networks in Venezuela

In July 2021, ESET revealed “Bandidos,” an active cyberespionage campaign that used an updated version of the Bandook remote access Trojan. Nearly 90% of the detections (more than 200 droppers in 2021) were concentrated in Venezuela, affecting corporate networks in the manufacturing, construction, healthcare, software services, and retail sectors. The infection began with spear-phishing emails containing PDF files that linked to compressed droppers capable of stealing documents and credentials.

Impact details

ESET documented the Bandidos campaign, which used Bandook to target corporate networks in Venezuela, with more than 200 detections of droppers in 2021 and capabilities to steal credentials and documents, take screenshots, and record audio and video.

credentialssensitive documentssystem informationscreenshotsaudio recordingswebcam video

Classification & severity

Category
Malicious code
Subtype
spyware remote access trojan
Confidence
High

ESET documented espionage activity targeting corporate networks in Venezuela using the Bandook/Bandidos malware.

Severity assessment

High
Information impact
Credentials
Affected scope
Cross-sector
Critical service
None
Public confidence
Limited
Recoverability
Extended

Verified spyware/RAT campaign capable of stealing credentials and documents across multiple Venezuelan business sectors.

Data exfiltration· Confirmed Confidentiality

Timeline

Disclosure

ESET has published its investigation into the “Bandidos” campaign, detailing the use of the updated Bandook RAT against corporate networks, with approximately 90% of detections occurring in Venezuela.

Compromise

More than 200 detections of malware droppers were documented in Venezuela during 2021, distributed via spear-phishing emails containing PDFs that linked to compressed files on cloud storage services.

Evidence & sources

3 sources