BONDUPDATER is a PowerShell-based downloader/remote-access trojan associated with the Iranian threat group OilRig (APT34). Reporting in the provided content places OilRig use of BONDUPDATER as early as mid-2017, including campaigns against Middle Eastern government targets and broader targeting aligned with OilRig’s focus on government, financial, energy, chemical, and telecommunications organizations in the Middle East. It has also been described in leaked OilRig tooling as a BondUpdater RAT variant under names including PoisonFrog and Glimpse.
Observed infection chains in the content include spear-phishing with malicious RTF documents exploiting CVE-2017-0199 and CVE-2017-11882. In one documented chain, exploitation launched mshta.exe, which retrieved a script that downloaded additional VBS, BAT, and PowerShell components. Persistence was then established via a scheduled task that executed every minute, ultimately launching PowerShell payloads including BONDUPDATER. BONDUPDATER also uses PowerShell with -windowstyle hidden to conceal the download/execution window from the victim.
Capabilities directly described in the content include use of a custom domain generation algorithm (DGA) to generate subdomains for command-and-control communications; DNS tunneling over A and TXT records; downloading and uploading files; and reading batch commands from a file sent by the C2 server and executing them with cmd.exe. Unit 42 reporting in the content describes early variants using System.Net.Dns GetHostAddresses and an updated variant capable of using raw sockets via System.Net.Sockets.UdpClient, with the updated version able to switch to a TXT-record-based tunnel. Early variants created a unique system identifier from the first 12 characters of whoami output and used beacon subdomains ending in B007.<C2 domain>. The content also notes specific protocol markers, including IPv4 11.24.237.110 as a termination signal, IPv4 99.250.250.199 to switch to alternate TXT-based tunneling, and TXT control instructions such as N, S, S000s, E, and C governing file creation, base64 decoding, writing data, and canceling communications.
The malware is described as supporting sustained access in OilRig intrusions, alongside webshell installation, credential theft enabling lateral movement, intelligence collection on communications and decision-making, and document exfiltration targeting policy and strategic planning materials. High-confidence indicators and artifacts mentioned in the content include URLs hxxp://mumbai-m[.]site/b.txt and hxxp://dns-update[.]club/v.txt from a documented delivery chain, the C2 domain proxychecker[.]pro in earlier activity, and dropped files hUpdateCheckers.ps1, dUpdateCheckers.ps1, cUpdateCheckers.bat, GoogleUpdateschecker.vbs, hUpdateCheckers.base, and dUpdateCheckers.base under C:\ProgramData\Windows\Microsoft\java.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Key TTPs: Persistent access through webshell installation; credential theft enabling lateral movement; intelligence collection on communications and decision-making; malware deployment (BONDUPDATER or TONEDEAF) for sustained access; document exfiltration targeting policy and strategic planning materials.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions. | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by APT34 for sustained access during espionage operations against government, technology, and energy-related targets.
Backdoor malware used by OilRig for persistent access and command and control.
Backdoor that persists through a scheduled task running every minute.
A PowerShell-written malware/backdoor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.