TriFive is a PowerShell-based backdoor associated with the xHunt espionage cluster, which has targeted organizations in Kuwait, particularly in government, shipping, and transportation. It was identified during compromises involving Microsoft Exchange Server and related IIS infrastructure, where xHunt maintained long-term access using scheduled-task persistence, covert command-and-control channels, and companion tooling such as the BumbleBee web shell and the Snugy backdoor.
TriFive is designed for remote command execution and post-compromise control. It was observed running repeatedly via a scheduled task at five-minute intervals, indicating persistent beaconing and automated task-based execution. Its command-and-control mechanism abuses a legitimate compromised mailbox on the victim Exchange server through Exchange Web Services. The implant retrieves commands from specially formatted draft messages stored in the Deleted Items folder, decodes and transforms the message content, executes the resulting PowerShell commands, and writes command output back into draft messages in the same mailbox. This mailbox-draft workflow is intended to blend malicious traffic with normal enterprise email activity and reduce reliance on conventional external C2 infrastructure.
Observed activity shows TriFive being used after initial compromise rather than as the initial access vector. In the documented intrusions, attackers had already obtained access to Exchange infrastructure and stolen or otherwise acquired valid account credentials. The malware formed part of a broader xHunt intrusion set that included web-shell-enabled command execution, credential abuse, persistence through masqueraded scheduled tasks, and lateral movement across internal systems. TriFive reflects xHunt’s emphasis on stealthy, living-off-trusted-services tradecraft and covert communications within compromised Microsoft messaging environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The activity we observed involved two backdoors – one of which we call TriFive and a variant of CASHY200 that we call Snugy – as well as a web shell that we call BumbleBee.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
The TriFive sample used a legitimate account name and credentials from the targeted organization. This suggests that the threat actor had stolen the account's credentials prior to the installation of the TriFive backdoor.
This investigation resulted in the discovery of two new backdoors called TriFive and Snugy... as well as a new webshell that we call BumbleBee... The actor used the BumbleBee webshell to upload and download files to and from the compromised Exchange server, but more importantly, to run commands that the actor used to discover additional systems and to move laterally to other servers on the network.
On Aug. 28 and Oct. 22, 2019, the actors created the ResolutionHosts and ResolutionsHosts tasks to run two separate PowerShell-based backdoors. The actors used these two scheduled tasks as a persistence method, as they ran the two PowerShell scripts repeatedly, albeit at different intervals.
The script opens the email draft, base64 decodes the contents in the message body of the email and decrypts the decoded contents by subtracting 10 from each character.
Both of the backdoors installed on the compromised Exchange server of a Kuwait government organization used covert channels for C2 communications, specifically DNS tunneling and an email-based channel using drafts in the Deleted Items folder of a compromised email account.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PowerShell-based backdoor used by xHunt APT for command execution and persistent access via scheduled tasks.
PowerShell backdoor that uses Exchange Web Services/mailbox access for C2 by reading/writing encrypted, base64-encoded commands and results in email drafts (e.g., Deleted Items). Typically persisted via scheduled tasks with execution-policy bypass.
A backdoor associated with the xHunt campaign that repeatedly beaconed every five minutes on the compromised Exchange server, indicating sustained access and persistence via a scheduled task.
A previously unseen PowerShell-based backdoor that provides access to a compromised Microsoft Exchange server by logging into a legitimate user's mailbox, retrieving encrypted commands from email drafts in the Deleted Items folder via Exchange Web Services, executing them with PowerShell, and returning results through reply drafts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.