Bolik
Overview
Executive Summary
Bolik is a highly sophisticated Banking Trojan that emerged around 2016. Security researchers consider it a direct, advanced descendant of the infamous Zeus and Carberp banking trojans, as it shares significant portions of their leaked source code. Bolik is designed for high-end financial fraud, engineered to stealthily harvest banking credentials, intercept two-factor authentication (2FA) tokens, and execute unauthorized wire transfers from compromised corporate endpoints.Infection Vector and Technical Capabilities
Bolik is typically distributed through highly targeted spear-phishing campaigns (often disguised as B2B invoices or tax documents) containing weaponized Office documents, or via drive-by downloads from compromised websites (often utilizing the RIG Exploit Kit). Upon execution, Bolik demonstrates advanced, modular capabilities:- Web Injection (Man-in-the-Browser): Bolik's primary weapon is its web injection engine. When a victim logs into a targeted banking portal (e.g., Chase, Barclays), the trojan intercepts the browser traffic (Internet Explorer, Chrome, Firefox) and injects fraudulent HTML/JavaScript into the page. This allows attackers to steal login credentials, prompt for 2FA codes, or hide the true account balance.
- Reverse Connect (VNC) and Web-Proxy: The trojan establishes a reverse VNC connection, giving the attacker hidden, interactive access to the victim's desktop. It also sets up a local web proxy, allowing the attacker to route their fraudulent transactions through the victim's IP address, bypassing bank geolocation security checks.
- Fileless Evasion: Bolik heavily utilizes process hollowing and DLL injection (often targeting `explorer.exe` or `svchost.exe`) to execute its core payload directly in memory, making it highly resistant to traditional disk-based antivirus scanning.
Threat Assessment
A Bolik infection is a critical security incident. Because it specifically targets financial institutions and corporate banking portals, the presence of this trojan poses an immediate, severe risk of massive financial theft and corporate wire fraud.Incident Response and Remediation
- Immediate Network Isolation: Disconnect the infected machine immediately to sever the reverse VNC connection and prevent the attacker from executing fraudulent transactions.
- Emergency Financial Freeze: Notify the corporate treasury or finance department immediately. All banking credentials utilized on the infected machine must be frozen, and recent wire transfers must be audited for fraud.
- Volumetric Memory Analysis: Because Bolik operates largely filelessly, responding to the incident requires volatile memory (RAM) capture and analysis using advanced EDR tools to identify the injected processes and extract the specific banking configurations (target lists) the trojan was using.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1185 T1056.001 T1055 T1090
Tactical Mitigations
Based on the techniques used by this family, consider the following defensive strategies:
- T1056.001: Implement Endpoint Detection and Response (EDR) to monitor for suspicious API calls related to keystroke interception. Enforce Multi-Factor Authentication (MFA) to render stolen passwords useless.
- T1185: Enforce strong MFA and use browser isolation or hardened browsers for sensitive financial or administrative portals to defeat session hijacking.
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_BOLIK {
meta:
description = "Detects Bolik (trojan)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "bolik" ascii wide nocase
$s2 = "trojan-banker.win32.bolik" ascii wide nocase
$s3 = "carberp.variant" ascii wide nocase
$s4 = "win32/bolik" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Bolik Activity
id: 4a4f9e6e6b5314ac7c07889bdcb0dcb5
status: experimental
description: Detects generic indicators of the bolik malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*bolik*"
- "*trojan-banker.win32.bolik*"
- "*carberp.variant*"
- "*win32/bolik*"
condition: selection
level: mediumReferences & External Analysis
- Search "bolik" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Bolik Trojan from Windows?
Manual removal of Bolik is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Bolik a virus or a Trojan?
Bolik is classified as a Trojan. Unlike traditional viruses that infect files, modern malware like Bolik typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Bolik infection?
Symptoms of Bolik can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: trojan)
Explore other malware families in the same category:
Protect Your Network Against Trojans
Want to prevent Bolik and similar threats from compromising your organization? Read our comprehensive defensive guide: Banking Trojan Protection.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/bolik.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.