Uptime Hamster: 10d 12h 29mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza BuhTrap

BuhTrap

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: UAC-0008, Ratopak, AmmyAdmin, LURK, Mimikatz, la vulnerabilidad CVE-2012-0158, gobiernos
Ver en IntelTracker → APTTrail →
BuhTrap is a cybercriminal group that emerged in late 2014, initially focusing on financial fraud by targeting banking clients and institutions in Russia and the surrounding region. The group's operations evolved significantly, shifting in late 2015 from purely financially motivated attacks to include cyber espionage campaigns targeting governmental institutions in Eastern Europe and Central Asia. Originally utilizing a banking Trojan, BuhTrap's malware and operational tactics expanded to incorporate advanced espionage capabilities, including the use of zero-day exploits, marking a clear evolution in their objectives and sophistication. This transition from a financial crime focus to cyber espionage, coupled with their documented use of previously unknown vulnerabilities, distinguishes them from many other financially motivated groups. While the source code for some of their tools was leaked in 2016, the group has continued to operate, with high confidence attribution linking them to a

Aliases del actor

UAC-0008RatopakAmmyAdminLURKMimikatzla vulnerabilidad CVE-2012-0158gobiernos

Actores similares

uac-0008actor · 1cve-2023-41991actor · 1cve-2023-36884actor · 1mimikatzactor · 1UAC-0194apt · 0UAC-0185apt · 0UAC-0020apt · 0UAC-0219apt · 0UAC-0149apt · 0UAC-0215apt · 0
Motivacion