SYMBOLCOMMON_NAMEaka. SYNONYMS
win.bookcodesrat (Back to overview)

BookCodes RAT

aka: BookCodesTea

Actor(s): Lazarus Group

VTCollection    

BookCodesRAT is a remote access trojan that uses HTTP(S) for communication. It supports around 25 commands that include operations on the victim’s filesystem, basic process management and the download and execution of additional tools from the attacker’s arsenal. They are indexed by 32-bit integers, starting with the value 0x97853646.

BookCodesRAT uses mostly compromised South Korean web servers for the C&C traffic and is usually deployed against South Korean targets.

References
2021-10-08 ⋅ Virus Bulletin ⋅ Seongsu Park
Multi-universe of adversary: multiple campaigns of the Lazarus group and their connections
Dacls AppleJeus AppleJeus Bankshot BookCodes RAT Dacls DRATzarus LCPDot LPEClient
2021-10-07 ⋅ Virus Bulletin ⋅ Byeongjae Kim, Dongwook Kim, Taewoo Lee
Operation Bookcodes – targeting South Korea
BookCodes RAT LPEClient
2020-12-23 ⋅ Kaspersky Labs ⋅ Seongsu Park
Lazarus covets COVID-19-related intelligence
BookCodes RAT wAgentTea
2020-11-16 ⋅ ESET Research ⋅ Anton Cherepanov, Peter Kálnai
Lazarus supply‑chain attack in South Korea
BookCodes RAT Lazarus Group
2020-06-29 ⋅ KISA ⋅ KrCERT
OPERATION BOOKCODES TTPs #2
BookCodes RAT
2020-04-01 ⋅ KISA ⋅ KrCERT
OPERATION BOOKCODES TTPs #1
BookCodes RAT
Yara Rules
[TLP:WHITE] win_bookcodesrat_auto (20260917 | Detects win.bookcodesrat.)
rule win_bookcodesrat_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.bookcodesrat."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bookcodesrat"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 4c89642448 4c89642450 4c89642458 4489642460 4c89642468 }
            // n = 5, score = 100
            //   4c89642448           | xor                 al, 0x33
            //   4c89642450           | inc                 edx
            //   4c89642458           | movzx               eax, byte ptr [ebp + eax + 0x360]
            //   4489642460           | dec                 ecx
            //   4c89642468           | inc                 eax

        $sequence_1 = { 488b542468 48897c1008 85ff 7925 833b00 0f8599feffff 488d4c2430 }
            // n = 7, score = 100
            //   488b542468           | mov                 eax, dword ptr [eax + 0x10]
            //   48897c1008           | dec                 eax
            //   85ff                 | mov                 ebx, ecx
            //   7925                 | xor                 ecx, ecx
            //   833b00               | mov                 dword ptr [esp + 0x38], ecx
            //   0f8599feffff         | push                ebx
            //   488d4c2430           | dec                 eax

        $sequence_2 = { 498bcd e8???????? 488b7c2420 488bd8 e9???????? 498b5520 488b4cf508 }
            // n = 7, score = 100
            //   498bcd               | test                dl, 1
            //   e8????????           |                     
            //   488b7c2420           | je                  0x7d5
            //   488bd8               | mov                 edx, esi
            //   e9????????           |                     
            //   498b5520             | dec                 eax
            //   488b4cf508           | mov                 ecx, eax

        $sequence_3 = { 488d4c2460 e8???????? 41b820000000 488d15b4b70200 488d4c2460 e8???????? 41b810000000 }
            // n = 7, score = 100
            //   488d4c2460           | je                  0xfac
            //   e8????????           |                     
            //   41b820000000         | dec                 ecx
            //   488d15b4b70200       | mov                 ecx, esi
            //   488d4c2460           | dec                 ecx
            //   e8????????           |                     
            //   41b810000000         | sub                 ecx, edi

        $sequence_4 = { 3433 428884058f070000 83fa14 7ce4 4863c2 4c8bc1 8bd1 }
            // n = 7, score = 100
            //   3433                 | je                  0x1998
            //   428884058f070000     | inc                 ebp
            //   83fa14               | xor                 ecx, ecx
            //   7ce4                 | dec                 esp
            //   4863c2               | mov                 eax, esi
            //   4c8bc1               | dec                 eax
            //   8bd1                 | mov                 edx, ebx

        $sequence_5 = { 488d9580010000 488d8f30330000 41b808020000 448bce e8???????? e9???????? 448b4308 }
            // n = 7, score = 100
            //   488d9580010000       | mov                 byte ptr [ebp + 0x279], al
            //   488d8f30330000       | mov                 dword ptr [ebp + 0x294], 0x2440265f
            //   41b808020000         | inc                 esp
            //   448bce               | mov                 byte ptr [ebp + 0x260], ch
            //   e8????????           |                     
            //   e9????????           |                     
            //   448b4308             | inc                 ecx

        $sequence_6 = { 41b820000000 488d15edba0200 488d4c2448 e8???????? 41b810000000 488d151ebb0200 }
            // n = 6, score = 100
            //   41b820000000         | cmp                 ebp, esp
            //   488d15edba0200       | je                  0x1927
            //   488d4c2448           | xor                 eax, eax
            //   e8????????           |                     
            //   41b810000000         | dec                 eax
            //   488d151ebb0200       | cmp                 dword ptr [ebx + 0x18], 8

        $sequence_7 = { 488d8d40010000 e8???????? 488d9540010000 48895508 41b918000000 4c8d4500 418d510e }
            // n = 7, score = 100
            //   488d8d40010000       | and                 ecx, 0x800000ff
            //   e8????????           |                     
            //   488d9540010000       | mov                 byte ptr [ecx - 1], al
            //   48895508             | jne                 0x23c
            //   41b918000000         | dec                 ecx
            //   4c8d4500             | add                 ecx, 0x28
            //   418d510e             | dec                 ebp

        $sequence_8 = { 488d442460 33c9 c744245404010000 c744245004010000 4889442420 ff15???????? 85c0 }
            // n = 7, score = 100
            //   488d442460           | lea                 edx, [esp + 0x60]
            //   33c9                 | dec                 eax
            //   c744245404010000     | lea                 ecx, [ebx + 0x210]
            //   c744245004010000     | dec                 eax
            //   4889442420           | sub                 edx, ecx
            //   ff15????????         |                     
            //   85c0                 | cmp                 edx, 2

        $sequence_9 = { 6683387c 0f859f000000 4883c002 4c8d442460 488bd7 488bcb 488907 }
            // n = 7, score = 100
            //   6683387c             | test                eax, eax
            //   0f859f000000         | js                  0x1cf
            //   4883c002             | dec                 ecx
            //   4c8d442460           | mov                 edx, edi
            //   488bd7               | dec                 esp
            //   488bcb               | cmp                 edi, dword ptr [ebx + 0x10]
            //   488907               | jb                  0x153

    condition:
        7 of them and filesize < 544768
}
Download all Yara Rules