Bateleur
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers have uncovered that the threat actor commonly referred to as FIN7 has added a new JScript backdoor called Bateleur... starting in early June, we observed this threat actor using macro documents to drop a previously undocumented JScript backdoor, which we have named “Bateleur”.
Proofpoint researchers have uncovered that the threat actor commonly referred to as FIN7 has added a new JScript backdoor called Bateleur... starting in early June, we observed this threat actor using macro documents to drop a previously undocumented JScript backdoor, which we have named “Bateleur”.
Techniques & procedures
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 technique
Initial Access
Execution
6 techniques
Execution
wexe Perform a “load_exe” request to C&C to retrieve an EXE, save it as debug.log and then execute the EXE via WMI ... wpowershell Same as powershell command but instead executes a PowerShell command via WMI
the macro executes the following commands... schtasks /create /f /tn ""GoogleUpdateTaskMachineCorefh5evfbce5bhfd37"" /tr ""wscript.exe //b /e:jscript %TMP%\debug.txt "" ... When Bateleur first executes it creates a scheduled task “ GoogleUpdateTaskMachineSystem” for persistence
The malicious JScript has robust capabilities that include... execution of custom commands and PowerShell scripts... powershell Perform a “load_powershell” request to the C&C to retrieve a command to execute... apowershell Same as powershell command but instead executes a PowerShell command directly with powershell.exe
cmd Perform a “load_cmd” request to the C&C to retrieve a command to execute... execute debug.cmd with cmd.exe
Persistence
1 technique
Persistence
the macro executes the following commands... schtasks /create /f /tn ""GoogleUpdateTaskMachineCorefh5evfbce5bhfd37"" /tr ""wscript.exe //b /e:jscript %TMP%\debug.txt "" ... When Bateleur first executes it creates a scheduled task “ GoogleUpdateTaskMachineSystem” for persistence
Privilege Escalation
1 technique
Privilege Escalation
the macro executes the following commands... schtasks /create /f /tn ""GoogleUpdateTaskMachineCorefh5evfbce5bhfd37"" /tr ""wscript.exe //b /e:jscript %TMP%\debug.txt "" ... When Bateleur first executes it creates a scheduled task “ GoogleUpdateTaskMachineSystem” for persistence
Stealth
4 techniques
Stealth
The new macros and Bateleur backdoor use sophisticated anti-analysis and sandbox evasion techniques... the first FIN7 change we observed was in the obfuscation technique found in their usual document attachments... The caption contains a “|*|”-delimited obfuscated JScript payload.
dll Perform a “load_dll” request to the C&C to retrieve a DLL... write a regsvr32 command to a file named debug.cmd and then execute debug.cmd with cmd.exe
Credential Access
1 technique
Credential Access
Discovery
4 techniques
Discovery
get_information Return various information about the infected machine, such as computer and domain name, OS, screen size, and net view
Collection
1 technique
Collection
IOCs tracked for this family
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.