Malware.View on attack.mitre.org
BONDUPDATER is a PowerShell backdoor used by OilRig. It was first observed in November 2017 during targeting of a Middle Eastern government organization, and an updated version was observed in August 2018 being used to target a government organization with spearphishing emails.
| Technique | Procedure example |
|---|---|
| T1053.005 Scheduled Task |
BONDUPDATER persists using a scheduled task that executes every minute. |
| T1059.001 PowerShell |
BONDUPDATER is written in PowerShell. |
| T1059.003 Windows Command Shell |
BONDUPDATER can read batch commands in a file sent from its C2 server and execute them with cmd.exe. |
| T1071.004 DNS |
BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control. |
| T1105 Ingress Tool Transfer |
BONDUPDATER can download or upload files from its C2 server. |
| T1564.003 Hidden Window |
BONDUPDATER uses |
| T1568.002 Domain Generation Algorithms |
BONDUPDATER uses a DGA to communicate with command and control servers. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.