PoisonFrog is a PowerShell-based remote access trojan associated with the Iranian threat group OilRig, also tracked as APT34, and is widely described as an older version of BondUpdater. It is designed for covert command and control over DNS, using recursive A-record lookups to exchange tasking and results without requiring direct connections to attacker infrastructure. The malware encodes control data and payload fragments into crafted DNS subdomains, processes responses from returned IP address data, and supports execution of PowerShell commands as well as file upload and download operations. Large transfers are performed in small chunks, producing bursts of DNS traffic consistent with tunneling behavior.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
PoisonFrog: an old version of BondUpdater ... The leaked sample used two remote access Trojans (RATs), poisonfrog.ps1 (old version) and Glimpse ( dns_main.ps1 ) (new version).
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog post, the IronNet Threat Research team examines the PoisonFrog malware that is written in PowerShell and has been associated to OilRig/APT34.
"...used Iranian web shells and COBALT GYPSY's PoisonFrog C2 administration panels to deliver its own malware."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
At its core, PoisonFrog is a PowerShell script designed to be invoked every ten minutes by setting itself up as a Windows task.
the attacker will create a scheduled task to execute the PowerShell script regularly... As a scheduled task, the vbs script is set to execute every 10 minutes.
In this blog post, the IronNet Threat Research team examines the PoisonFrog malware that is written in PowerShell.
At its core, PoisonFrog is a PowerShell script designed to be invoked every ten minutes by setting itself up as a Windows task.
Should the malware be unable to communicate over DNS, PoisonFrog comes packaged with an HTTP-based version of itself which runs concurrently with the DNS tunneling PowerShell script.
"...used Iranian web shells and COBALT GYPSY's PoisonFrog C2 administration panels to deliver its own malware."
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PoisonFrog is referenced as another DNS-tunneling malware sample in the same series, used for comparison with RogueRobin’s communications approach.
An older PowerShell RAT variant used to steal information from compromised servers and execute CMD commands from C2. It uploads/downloads files, can use proxy-aware communications, and persists via scheduled tasks.
PowerShell malware that uses DNS tunneling for command-and-control, tasking, file upload/download, and execution of PowerShell commands. It registers with its controller, checks for tasks on a scheduled basis, processes them, and exfiltrates results via crafted DNS A-record queries. The sample also includes an HTTP-based fallback variant for C2.
A variant/version of the BondUpdater remote-access trojan used for remote control of compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.