ATT&CKSoftwareBONDUPDATER

BONDUPDATER

S0360

Malware.View on attack.mitre.org

About this malware

BONDUPDATER is a PowerShell backdoor used by OilRig. It was first observed in November 2017 during targeting of a Middle Eastern government organization, and an updated version was observed in August 2018 being used to target a government organization with spearphishing emails.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1053.005
Scheduled Task

BONDUPDATER persists using a scheduled task that executes every minute.

T1059.001
PowerShell

BONDUPDATER is written in PowerShell.

T1059.003
Windows Command Shell

BONDUPDATER can read batch commands in a file sent from its C2 server and execute them with cmd.exe.

T1071.004
DNS

BONDUPDATER can use DNS and TXT records within its DNS tunneling protocol for command and control.

T1105
Ingress Tool Transfer

BONDUPDATER can download or upload files from its C2 server.

T1564.003
Hidden Window

BONDUPDATER uses -windowstyle hidden to conceal a PowerShell window that downloads a payload.

T1568.002
Domain Generation Algorithms

BONDUPDATER uses a DGA to communicate with command and control servers.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye APT34 Dec 2017 Open source
    Sardiwal, M, et al. (2017, December 7). New Targeted Attack in the Middle East by APT34, a Suspected Iranian Threat Group, Using CVE-2017-11882 Exploit. Retrieved December 20, 2017.
  2. Palo Alto OilRig Sep 2018 Open source
    Wilhoit, K. and Falcone, R. (2018, September 12). OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government. Retrieved February 18, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.