BoomBox is a custom Windows .NET malware associated with Russian state-linked espionage activity overlapping with APT29, also known as NOBELIUM, including operations connected to the broader SolarWinds-era toolset. It has been identified as an early-stage implant and downloader used in diplomatic-targeting intrusion campaigns against foreign ministries, embassies, and related organizations, particularly in NATO and European Union countries.
BoomBox is designed for host reconnaissance, selective payload retrieval, and limited data theft. It can collect basic victim information such as the current username, perform LDAP queries against Active Directory to enumerate domain users including distinguished names, SAM account names, and display names, and search local systems for specific files and directories. It can also upload collected data to attacker-controlled per-victim folders in Dropbox and download additional payloads from Dropbox using an embedded access token. Reported functionality also includes persistence establishment and information stealing behavior.
Operationally, BoomBox has been observed in phishing-driven intrusion chains that relied on user interaction with malicious files. In related campaigns, victims were lured through diplomatic-themed spearphishing and malicious files delivered via techniques such as HTML smuggling, deceptive shortcut files, and DLL sideloading. BoomBox has also been executed through RunDLL32, and it includes execution guardrails by checking its working directory and the presence of an expected file before continuing. For evasion and masquerading, it can disguise malicious data strings as PDF content.
BoomBox is best understood as a reconnaissance-focused downloader within a larger espionage toolkit, enabling operators to profile victims, stage follow-on malware, and exfiltrate selected information while blending some traffic with legitimate cloud services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"If the device targeted was an Apple iOS device, the user was redirected to another server under NOBELIUM control, where the since-patched zero-day exploit for CVE-2021-1879 was served."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Grupa ta wiązana jest m.in. z kampanią zwaną „SOLARWINDS”, narzędziami „SUNBURST”, „ENVYSCOUT” i „BOOMBOX”
19 distinct techniques documented for this family, organized by ATT&CK tactic.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
APT29 has been observed gaining persistence via backdoor and web shell malware variants, manipulating and adding accounts to compromised networks, conducting password spraying attacks to gain access to additional accounts, scheduled tasks, adding Registry Run keys, hijacking legitimate application-specific startup scripts to run malware on system startup, and WMI event subscriptions.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
"Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "ADVSTORESHELL... strings... encrypted with an XOR-based algorithm; some strings are also encrypted with 3DES and reversed." / "APT29 has used encoded PowerShell commands." / "APT41 used VMProtected binaries..."
BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. Sandworm Team has used a tool to query Active Directory using LDAP.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Multiple actors and tools are described enumerating domain users/admins via Windows net commands (e.g., net user /domain, net group "Domain Admins" /domain), LDAP/AD queries (e.g., Get-ADUser, Get-ADGroupMember), and AD enumeration utilities (e.g., AdFind, BloodHound, AD Explorer).
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
Akira will exfiltrate victim data using applications such as Rclone. APT41 DUST exfiltrated collected information to OneDrive. BoomBox can upload data to dedicated per-victim folders in Dropbox. During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously reported malware/tool associated with NOBELIUM/APT29 in intelligence-gathering operations.
A named tool associated in the report with prior APT29/NOBELIUM espionage activity.
Backdoor capable of enumerating the username on a compromised host.
Enterprise New Software: ... BoomBox
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.