BONDUPDATER is a PowerShell-based backdoor used by the Iranian state-aligned threat group OilRig, also tracked as APT34 and Helix Kitten, in cyber-espionage operations primarily targeting government and business entities in the Middle East. It has been observed in use since at least 2017 and has appeared in spearphishing-led intrusion chains against government organizations. Internal OilRig naming linked leaked variants of this malware to Glimpse and Poison Frog, indicating multiple related implementations and ongoing development.
BONDUPDATER provides remote access capabilities including command execution, file upload, and file download. It is notable for using DNS tunneling for command-and-control, with variants supporting DNS A records and later TXT records to improve flexibility and throughput. Reporting also attributes domain generation algorithm functionality to BONDUPDATER for command-and-control communications. Some variants use file-based tasking workflows, staging commands and transferred data in local directories before execution or exfiltration.
On Windows systems, BONDUPDATER has been delivered through targeted spearphishing documents containing malicious macros that drop script components and establish persistence. A documented persistence mechanism uses a scheduled task configured to execute every minute. The malware also employs execution concealment through hidden PowerShell windows and includes logic to prevent multiple concurrent instances. In broader OilRig operations, BONDUPDATER has been used alongside credential theft, webshell deployment, and intelligence collection to maintain long-term access to victim environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
BONDUPDATER uses a DGA to communicate with command and control servers.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
By analyzing the data dump, we have been able to identify exactly how the BONDUPDATER backdoor and its server component functions... In addition, we discovered that the backdoors are actually called Glimpse and Poison Frog internally by OilRig and are functionally two different tools.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
In mid-August, the Oilrig threat group sent what appeared to be a highly targeted phishing email to a high-ranking office in a Middle Eastern nation... Attached to the email was a malicious document named “N56.15.doc” ... which contained a macro that attempted to install a new version of the BONDUPDATER Trojan.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The spear-phishing email had an attached Microsoft Word document that contained a macro responsible for installing a new variant of BONDUPDATER. | The macro finishes by running the dropped VBScript "AppPool.vbs" file by running "wscript C:\ProgramData\WindowsAppPool\AppPool.vbs".
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
they also conducted at least one attack campaign containing an updated variant of the BondUpdater Trojan (uses DNS tunneling) as its final payload. | They also created a new remote administration tool that supported HTTP and DNS communication.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by APT34 for sustained access during espionage operations against government, technology, and energy-related targets.
Downloader malware that conceals PowerShell windows while retrieving payloads.
Backdoor malware used by OilRig for persistent access and command and control.
PowerShell-written malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.