Netskope Threat Labs

Bunitu

ATP Sandbox Adv. Heuristics

Bunitu is a trojan that turns infected computers into proxy endpoints for remote clients, registering itself at startup with its address and open ports. Access to its proxies flows through criminal VPN services that sell the connections to other cybercriminals, so an infected machine contributes traffic to a wider proxy network without its owner's knowledge.

First seen
May 2023
Last seen
October 2026
Alert Name
Win32.Dropper.Bunitu