Skip to main content
Mallory
MalwareUsed by 1 actorExploits 1 CVE

Betabot

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2014-6332Windows OLE Automation Array Remote Code Execution VulnerabilityExploited in the wild

The first encounter I had with this CVE in exploit kit, was in the Sweet Orange... already containing CVE-2014-6332... Sweet Orange firing CVE-2014-6332 and DarkShell Call back... Here a more "standard" Sweet Orange : CVE-2014-6332 fired by Sweet Orange - And Betabot call back... Neutrino Firing CVE-2014-6332... Archie... CVE-2014-6332... Flash EK firing CVE-2014-6332... NB : it's in RIG and Angler | Here a more "standard" Sweet Orange : CVE-2014-6332 fired by Sweet Orange - And Betabot call back. 2014-11-21

via malware dontneedcoffeemalware.dontneedcoffee.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
RATicate

"...families of RATs and infostealers. These included Lokibot, Betabot, Formbook, and AgentTesla."

via sophos threat researchnews.sophos.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1566.001Spearphishing AttachmentEvidence1

"In a series of malspam campaigns dating back to November of 2019, an unidentified group sent out waves of installers that drop remote administration tool (RAT) and information stealing malware..."

Execution

2 techniques
T1203Exploitation for Client ExecutionEvidence1
TacticExecution

The first encounter I had with this CVE in exploit kit, was in the Sweet Orange... already containing CVE-2014-6332 ... Sweet Orange : The URL pattern are different... CVE-2014-6332 in Sweet Orange 2014-11-19

T1204User ExecutionEvidence1
TacticExecution

"...leverages concern about the global COVID-19 pandemic to convince victims to open the payloads."

T1055Process InjectionEvidence1

"After the decryption, shellcode3 injects the final payload in a child process."

Stealth

2 techniques
T1036MasqueradingEvidence1
TacticStealth

"...sent out waves of installers..." and "presenting the installer as a 'banking confirmation.'"

T1055Process InjectionEvidence1

"After the decryption, shellcode3 injects the final payload in a child process."

T1071Application Layer ProtocolEvidence2

Da Orangade firing CVE-2014-6332 and DarkShell Call back 2014-11-19 GET http://98.126.249 .92:82/index.html 200 OK (text/html) ... Here a more "standard" Sweet Orange : CVE-2014-6332 fired by Sweet Orange - And Betabot call back.

INDICATORS OF COMPROMISE

IOCs tracked for this family

106 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
6 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
100 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in app5 years ago
uri●●●●●●●●●●●●View more in app5 years ago
uri●●●●●●●●●●●●View more in app6 years ago
uri●●●●●●●●●●●●View more in app6 years ago
uri●●●●●●●●●●●●View more in app6 years ago
uri●●●●●●●●●●●●View more in app6 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching106

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.