Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-06 00:22:43 UTC Home > List all groups > List all tools > List all groups using tool Bart Tool: Bart Names Bart Category Malware Type Ransomware Description (Proofpoint) Bart ransomware appeared for exactly one day on June 24, 2016. It was a secondary payload downloaded by RockLoader, the initial payload in a large email campaign using zipped JavaScript attachments. The Bart ransom screen was visually similar to Locky’s but Bart had one important distinction: it could encrypt files without contacting a command and control server. However, we have not seen Bart since, suggesting that this was either an experiment or that the ransomware did not function as expected for TA505. Information Malpedia Playbook Last change to this tool card: 25 April 2021 Download this tool card in JSON format All groups using tool Bart Changed Name Country Observed APT groups TA505, Graceful Spider, Gold Evergreen 2006-Nov 2022 1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b83a611-9d11-4f1c-b4b5-a6854cb17df7 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b83a611-9d11-4f1c-b4b5-a6854cb17df7 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6b83a611-9d11-4f1c-b4b5-a6854cb17df7 Page 2 of 2