White Paper
Unraveling BatLoader and FakeBat
BatLoader and FakeBat are competing Russian-speaking malware-as-a-service groups that target corporate employees with various types of malware, including ransomware and banking trojans. These groups use sophisticated techniques to infiltrate organizations across multiple industries such as manufacturing, software, legal, retail, and healthcare. eSentire’s Threat Response Unit has actively tracked their operations and successfully intercepted and stopped numerous attacks affecting over 20 customers between September 2022 and November 2023. Through its investigations, the team has also identified key operators behind these campaigns, highlighting the importance of proactive threat intelligence and rapid response.
