ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool Bookworm

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: Bookworm

NamesBookworm
CategoryMalware
TypeBackdoor, Keylogger, Info stealer
Description(Palo Alto) Bookworm’s functional code is radically different from PlugX and has a rather unique modular architecture that warranted additional analysis by Unit 42. Bookworm has little malicious functionality built-in, with its only core ability involving stealing keystrokes and clipboard contents. However, Bookworm expands on its capabilities through its ability to load additional modules directly from its command and control (C2) server.
Information<https://unit42.paloaltonetworks.com/bookworm-trojan-a-model-of-modular-architecture/>

Last change to this tool card: 19 April 2020

Download this tool card in JSON format

Previous: Bookcode
Next: Boostwrite

All groups using tool Bookworm

ChangedNameCountryObserved

APT groups

 BookwormChina2015 

1 group listed (1 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key