Names | Bookworm | |
Category | Malware | |
Type | Backdoor, Keylogger, Info stealer | |
Description | (Palo Alto) Bookworm’s functional code is radically different from PlugX and has a rather unique modular architecture that warranted additional analysis by Unit 42. Bookworm has little malicious functionality built-in, with its only core ability involving stealing keystrokes and clipboard contents. However, Bookworm expands on its capabilities through its ability to load additional modules directly from its command and control (C2) server. | |
Information | <https://unit42.paloaltonetworks.com/bookworm-trojan-a-model-of-modular-architecture/> | |
Malpedia | <https://malpedia.caad.fkie.fraunhofer.de/details/win.bookworm> |
Last change to this tool card: 27 December 2022
Download this tool card in JSON format
Previous: Bookcode
Next: Boostwrite
Changed | Name | Country | Observed | ||
APT groups | |||||
Bookworm | 2015 |
1 group listed (1 APT, 0 other, 0 unknown)
Digital Service Security Center Follow us on |
Report incidents |
|
+66 (0)2-123-1227 | ||
[email protected] |