Operation Bandidos

Description

(ESET) In 2021 we detected an ongoing campaign targeting corporate networks in Spanish-speaking countries, with 90% of the detections in Venezuela. When comparing the malware used in this campaign with what was previously documented, we found new functionality and changes to this malware, known as Bandook. We also found that this campaign targeting Venezuela, despite being active since at least 2015, has somehow remained undocumented. Given the malware used and the targeted locale, we chose to name this campaign Bandidos.

Names

NameName-Giver
Operation BandidosESET

Country

Motivation

  • Information theft and espionage

First Seen

2021

Observed Countries

Tools

Information

Other Information

Uuid

bfea8c04-ab0d-41ac-a997-f5d9cdb740bc

Last Card Change

2021-08-09