Skip to content

Malware

ComLook

ComLook is a malicious plugin for the mail client "The Bat!", written in C++ and compiled with MSVC 10.0.

ComLook is a Windows malware family operated by Turla.

Background

ComLook is a malicious plugin for the "The Bat!" email client, written in C++ and built with MSVC 10.0. It supports malicious commands such as PutFile, GetFile, SetConfig, GetConfig, and Command. Hard-coded email addresses and other embedded data point to a target in Azerbaijan. First submitted to VirusTotal on January 12, 2022, it is linked to the APT group Turla and appears to be part of a targeted operation.


Source: Malpedia (Fraunhofer FKIE).