Bonadan

S0486

Malware.View on attack.mitre.org

About this malware

Bonadan is a malicious version of OpenSSH which acts as a custom backdoor. Bonadan has been active since at least 2018 and combines a new cryptocurrency-mining module with the same credential-stealing module used by the Onderon family of backdoors.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1016
System Network Configuration Discovery

Bonadan can find the external IP address of the infected host.

T1033
System Owner/User Discovery

Bonadan has discovered the username of the user running the backdoor.

T1057
Process Discovery

Bonadan can use the ps command to discover other cryptocurrency miners active on the system.

T1059
Command and Scripting Interpreter

Bonadan can create bind and reverse shells on the infected system.

T1082
System Information Discovery

Bonadan has discovered the OS version, CPU model, and RAM size of the system it has been installed on.

T1105
Ingress Tool Transfer

Bonadan can download additional modules from the C2 server.

T1496.001
Compute Hijacking

Bonadan can download an additional module which has a cryptocurrency mining extension.

T1554
Compromise Host Software Binary

Bonadan has maliciously altered the OpenSSH binary on targeted systems to create a backdoor.

T1573.001
Symmetric Cryptography

Bonadan can XOR-encrypt C2 communications.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET ForSSHe December 2018 Open source
    Dumont, R., M.Léveillé, M., Porcher, H. (2018, December 1). THE DARK SIDE OF THE FORSSHE A landscape of OpenSSH backdoors. Retrieved July 16, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.