Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

BetaBot—also known as Neurevt—shows how a relatively inexpensive malware builder could equip criminals with a wide range of capabilities, from stealing credentials to maintaining a foothold on an infected computer. Analyses published in 2017 and 2018 document its features and phishing delivery methods, but do not establish how prevalent it is today.

What was BetaBot?

BetaBot, also called Neurevt, first appeared in late 2012, according to Cybereason’s 2018 analysis, as reported by SecurityWeek. It was initially described as a banking Trojan and password stealer, then accumulated additional functions. Researchers described it as an infostealer with capabilities that could include capturing information entered into browser forms, stealing FTP and email-client credentials, and performing banking-related theft.

Other functions reported across the malware family included USB infection, distributed denial-of-service (DDoS) activity, a userland rootkit, command execution through a shell, persistence, and downloading additional malware. A cryptocurrency-mining module was added in late 2017. These are capabilities reported across versions and analyses; they should not be read as a checklist present in every sample.

How did BetaBot infect computers?

The 2018 phishing campaign

Cybereason’s 2018 campaign analysis describes generic phishing emails that tried to persuade recipients to open an apparent Word document. The attachment was a weaponized RTF file, and the reported infection chain exploited CVE-2017-11882 in Microsoft Office Equation Editor. The vulnerability had been patched in 2017; this account describes a historical campaign, not its status in current Office versions. Cybereason’s analysis and SecurityWeek’s report describe the campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical lesson is about the delivery method: a familiar-looking document can be a lure, and opening an attachment can expose a computer when software is unpatched. The sources describe this as a relatively broad phishing effort, not evidence that every BetaBot infection used this same route.

Other documented delivery and activity

An archived NHS England Digital alert, published in March 2017 and updated in June 2018, says infected hosts could be used to distribute malware. It lists remote commands for DDoS activity, downloading and executing files, stealing information from browser forms, and creating a SOCKS4 proxy. The alert warns that it may contain outdated information.

What made BetaBot difficult to detect and remove?

Persistence and evasion

In the analyzed 2018 variant, Cybereason reported that BetaBot injected itself into multiple running processes. If one process was terminated, another could restore the loader, making simple removal less reliable. Researchers also observed checks for virtual-machine and sandbox indicators, along with anti-debugging behavior—techniques intended to hinder analysis.

That analysis found the malware attempted to detect 30 security products and, in some cases, disable or remove them. The figure is a count of products it attempted to detect, not a measure of how many it successfully disabled. It describes one historical variant, not a current comparison of antivirus products. Cybereason details these behaviors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why local cleanup could be difficult

Kaspersky’s Beta Bot overview says the malware can disable local malware scans and block access to security websites, complicating remediation. If an infected computer cannot safely download security software or updates, Kaspersky describes using a clean computer to download them and transferring them with a USB drive, then reformatting that drive afterward. A flash drive is only a transfer method in this scenario; it is not a detector or a removal tool.

Why was BetaBot called “cheap”?

Historical reporting quoted different prices at different times. In a February 28, 2017 SecurityWeek report on Sophos research, the package was described as advertised for around $120. On October 3, 2018, SecurityWeek quoted Assaf Dahan, senior director of threat hunting at Cybereason’s Nocturnus Research, estimating that new builders sold for “~200$.” Those are separate historical reports, not directly comparable price quotes or current market prices.

Dahan also cautioned that attribution was difficult because old builders and BetaBot source code were available online in hacking forums, while new builders were reportedly sold cheaply. A low barrier to acquiring a builder could put sophisticated functions within reach of more operators, but the cited reports do not identify all the people behind the campaigns.

What should computer users take from the historical reports?

  • Treat unexpected attachments and links cautiously. Be especially wary of messages that pressure you to open a document or enable content. Cybereason recommends scrutinizing suspicious messages and avoiding attachments or links from unknown senders.
  • Install software and security updates promptly. The 2018 campaign’s use of an Office vulnerability patched in 2017 illustrates why updates matter; it does not mean that vulnerability remains unpatched on an up-to-date system.
  • Use a standard account for ordinary work. NHS England Digital’s archived alert recommends avoiding administrator privileges for routine activity, which can limit what some malware can change.
  • Respond to suspected infection from a clean device. If credentials may have been exposed, use a separate, trusted computer to change affected passwords and secure accounts. NHS England Digital specifically advises resetting accounts accessed from an infected machine using a clean computer; follow current incident-response guidance from your organization or security provider as appropriate.
  • Review network and security logs when investigating an incident. The archived NHS alert recommends monitoring network, proxy, and firewall logs. Its page is historical guidance and may not reflect current procedures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the historical record does—and does not—show

The 2017–2018 reporting establishes that BetaBot was a flexible malware family, documents specific capabilities and a phishing campaign, and records historical builder-price estimates. It does not provide a reliable current prevalence figure or establish that the documented campaigns, prices, or security-product observations describe conditions today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.