December 16, 2019 By David Bisson 2 min read

The BuleHero botnet was seen using multiple modules to move laterally on a network and increase the spread of its two payloads, the XMRig miner and the Gh0st remote-access Trojan (RAT).

ZScaler uncovered that the BuleHero botnet derived its name from the domain bulehero[.]in found in its binary. Closer analysis of the malware revealed that BuleHero used Swpuhostd.exe to drop a port scanning tool so the botnet could scan for exposed and vulnerable machines connected to the network. Researchers observed the threat sequentially scanning for IP addresses with ports 80 and 3389 open. It then saved these results into a Results.txt file.

In the samples it analyzed, ZScaler discovered that BuleHero used those port scanning results together with Mimikatz to dump passwords from infected hosts. It then gave those passwords to PsExec and WMIC, tools that helped the malware spread to other machines on the network. At that time, the botnet dropped XMRig miner and Gh0st RAT as its embedded malware payloads.

The Growing Prevalence of Lateral Movement

The BuleHero botnet isn’t the only recently discovered threat known for using lateral movement to spread across a network and infect other machines. At the beginning of December, for instance, IBM X-Force uncovered a new wiper called ZeroCleare that spread to numerous devices on an affected network in an effort to target energy organizations in the Middle East.

Around the same time, SentinelOne revealed that TrickBot had embraced new techniques allowing it to automatically collect network information and move laterally within networks. Also in December, the Microsoft Threat Intelligence Center disclosed its discovery of GALLIUM, a threat group known for using Mimikatz to obtain credentials for the purpose of moving laterally on an affected network.

How to Defend Against the BuleHero Botnet

Security professionals can help their organizations defend against the BuleHero botnet by leveraging user behavior analytics (UBA) to identify patterns that could point to potentially malicious behavior on the network. Companies should also invest in figuring out where their organization’s sensitive data resides, where it comes from and where it’s typically going so that they can monitor for suspicious processes involving that information.

More from

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

4 ways to bring cybersecurity into your community

4 min read - It’s easy to focus on technology when talking about cybersecurity. However, the best prevention measures rely on the education of those who use technology. Organizations training their employees is the first step. But the industry needs to expand the concept of a culture of cybersecurity and take it from where it currently stands as an organizational responsibility to a global perspective.When every person who uses technology — for work, personal use and school — views cybersecurity as their responsibility, it…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today