BuhTrap
Also reported as Buhtrap, Ratopak Spider and UAC-0008. Linked to Russia by three sources.
Reports per quarter
CVEs named in reports
- CVE-2008-4250 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2013-3660 KEV
- CVE-2014-4114 KEV
- CVE-2015-0057
- CVE-2015-1641 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1770 KEV
- CVE-2015-2387 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2016-0040 KEV
Show all 51 CVEs Show fewer
- CVE-2016-0165 KEV
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-7255 KEV ransomware
- CVE-2017-0001 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2018-0802 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-6055
- CVE-2018-8174 KEV ransomware
- CVE-2018-8453 KEV ransomware
- CVE-2018-8641
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-1069 KEV ransomware
- CVE-2019-1132 KEV
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-8518
- CVE-2020-0787 KEV ransomware
- CVE-2021-22941 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2025-0411 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor SmokeLoader (Malware Family)
-
Buhtrap, Ratopak Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Buhtrap, Ratopak Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
TA505, Graceful Spider, Gold Evergreen
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TA505, Graceful Spider, Gold Evergreen
-
Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Graphology of an Exploit – Hunting for exploits by looking for the author’s fingerprints
-
SCYTHE Library: #ThreatThursday - Buhtrap
The original link failed its last check. Original publisher Detailsfor SCYTHE Library: #ThreatThursday - Buhtrap
-
Operation TA505- network infrastructure. Part 3.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation TA505- network infrastructure. Part 3.
-
Operation TA505: network infrastructure. Part 3
The original link failed its last check. Original publisher Detailsfor Operation TA505: network infrastructure. Part 3
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Buhtrap group uses zero‑day in latest espionage campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Buhtrap group uses zero‑day in latest espionage campaigns
Show all 34 reports Show fewer
-
Buhtrap group uses zero‑day in latest espionage campaigns
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Buhtrap group uses zero‑day in latest espionage campaigns
-
Buhtrap backdoor and Buran ransomware distributed via major advertising platform
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Buhtrap backdoor and Buran ransomware distributed via major advertising platform
-
Cybercrime is focusing on accountants
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cybercrime is focusing on accountants
-
Silence: Moving into the darkside
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Silence: Moving into the darkside
-
Arrests Put New Focus on CARBON SPIDER Adversary Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Arrests Put New Focus on CARBON SPIDER Adversary Group
-
NotCarbanak Mystery - Source Code Leak
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor NotCarbanak Mystery - Source Code Leak
-
Cobalt Renaissance- new attacks and joint operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Renaissance- new attacks and joint operations
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hi-Tech Crime Trends 2016
-
The original link failed its last check. Original publisher Detailsfor Cobalt-Snatch-eng.pdf
-
Highly Evasive Code Injection Awaits User Interaction Before Delivering Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Highly Evasive Code Injection Awaits User Interaction Before Delivering Malware
-
Operation Buhtrap malware distributed via ammyy.com
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Buhtrap malware distributed via ammyy.com
-
Operation Buhtrap, the trap for Russian accountants
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Buhtrap, the trap for Russian accountants
Newest first. Details opens the report in Explore.