BUBBLEWRAP is a full-featured second-stage backdoor associated with the admin@338 threat group. It has been used after initial compromise to provide persistent remote access on victim systems, including automatic execution at system boot. The malware supports extensibility through plug-in management functions that allow operators to check for, upload, and register additional modules, enabling post-compromise capability expansion.
BUBBLEWRAP communicates with command-and-control infrastructure over HTTP and HTTPS and can also operate through SOCKS-based proxying. It has been observed as a follow-on payload delivered after target validation and reconnaissance in spearphishing-led intrusions, where an earlier-stage implant was used to collect host and network information before operators deployed BUBBLEWRAP for deeper access. Its role as a second-stage implant indicates use in sustained espionage-oriented operations rather than opportunistic mass infection.
The malware has been linked to campaigns targeting organizations of intelligence interest, including financial and policy-related entities, and to operations involving traditional Chinese-language lures aimed at Hong Kong-related targets. BUBBLEWRAP is also known by the detection name Backdoor.APT.FakeWinHTTPHelper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The spear phishing emails contained three attachments in total, each of which exploited an older vulnerability in Microsoft Office (CVE-2012-0158)
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group. It is set to run when the system boots and includes functionality to check, upload, and register plug-ins that can further enhance its capabilities.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A full-featured second-stage backdoor that achieves persistence at system boot and supports plug-in management, including checking, uploading, and registering plug-ins to extend functionality.
Malware that can use HTTP/HTTPS for communications (including C2).
Malware capable of communicating over HTTP or HTTPS.
Malware/tool that can communicate via SOCKS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.