BuhTrap is a cybercriminal group that emerged in late 2014, initially focusing on financial fraud by targeting banking clients and institutions in Russia and the surrounding region. The group's operations evolved significantly, shifting in late 2015 from purely financially motivated attacks to include cyber espionage campaigns targeting governmental institutions in Eastern Europe and Central Asia. Originally utilizing a banking Trojan, BuhTrap's malware and operational tactics expanded to incorporate advanced espionage capabilities, including the use of zero-day exploits, marking a clear evolution in their objectives and sophistication. This transition from a financial crime focus to cyber espionage, coupled with their documented use of previously unknown vulnerabilities, distinguishes them from many other financially motivated groups. While the source code for some of their tools was leaked in 2016, the group has continued to operate, with high confidence attribution linking them to a