ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool BendyBear

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: BendyBear

NamesBendyBear
CategoryMalware
TypeBackdoor
Description(Palo Alto) The BendyBear sample was determined to be x64 shellcode for a stage-zero implant whose sole function is to download a more robust implant from a command and control (C2) server. Shellcode, despite its name, is used to describe the small piece of code loaded onto the target immediately following exploitation, regardless of whether or not it actually spawns a command shell. At 10,000+ bytes, BendyBear is noticeably larger than most, and uses its size to implement advanced features and anti-analysis techniques, such as modified RC4 encryption, signature block verification, and polymorphic code.
Information<https://unit42.paloaltonetworks.com/bendybear-shellcode-blacktech/>

Last change to this tool card: 18 April 2021

Download this tool card in JSON format

Previous: Bemstour
Next: Benghazi.exe

All groups using tool BendyBear

ChangedNameCountryObserved

APT groups

 BlackTech, Circuit Panda, Radio PandaChina2010-2020 

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key