Adbupd is a PLATINUM-associated malware family used in cyber-espionage operations. Microsoft has identified Adbupd as one of several malware families used by the China-based threat group PLATINUM, which has targeted governments and related organizations in South and Southeast Asia and has been active since at least 2009. The malware is described as supporting plugins, allowing it to be specialized and adapted to victim protections. Reported capabilities and behaviors include encrypting command-and-control traffic using an embedded copy of the OpenSSL library, using a WMI script to achieve persistence, and running a copy of cmd.exe. The provided content does not include specific indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Multiple actors and tools (e.g., APT29, APT33, FIN8, Turla, Blue Mockingbird, PoshC2, POSHSPY, RegDuke, SeaDuke) are described as using WMI event subscriptions/filters/consumers to establish persistence, including triggering at system boot or on specific process start (e.g., WINWORD.EXE).
Multiple actors and tools (e.g., APT29, APT33, FIN8, Turla, Blue Mockingbird, PoshC2, POSHSPY, RegDuke, SeaDuke) are described as using WMI event subscriptions/filters/consumers to establish persistence, including triggering at system boot or on specific process start (e.g., WINWORD.EXE).
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that can use a WMI script to establish persistence on a compromised system.
Malware that encrypts command-and-control traffic using the OpenSSL library.
A PLATINUM-associated plugin-capable modular malware family designed to be extensible and adaptable to different defensive controls.
Uses an embedded OpenSSL library to encrypt command-and-control (C2) traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.