BendyBear
S0574 · Windows
BendyBear is an x64 shellcode for a stage-zero implant designed to download malware from a C2 server. First discovered in August 2020, BendyBear shares a variety of features with Waterbear, malware previously attributed to the Chinese cyber espionage group BlackTech.
ATT&CK S0574
Sigma rules0
YARA rules0
Live IOCs0