Glimpse is a PowerShell-based remote access trojan associated with the Iranian threat group APT34, also known as OilRig. It is widely assessed as a newer variant of the BondUpdater malware family and has been observed in leaked APT34 tooling alongside related implants such as PoisonFrog. Glimpse uses DNS tunneling as a covert command-and-control channel, allowing operators to issue tasking and receive results through crafted DNS traffic rather than conventional direct network connections. This tradecraft is intended to blend malicious communications into routine name-resolution activity and reduce visibility to traditional perimeter controls.
The malware is designed for remote control and post-compromise operations. Reported BondUpdater-family capabilities include execution of PowerShell commands, transfer of files, and exfiltration of task results over DNS-based communications. In APT34 operations, these implants have also been paired with scheduled-task persistence so that PowerShell scripts execute regularly to retrieve commands and maintain access. Glimpse has been linked to campaigns targeting organizations in the Middle East and other regions, particularly in government, financial, energy, telecommunications, and related sectors.
Operational reporting ties Glimpse to broader OilRig intrusion activity that relied on PowerShell tooling, DNS-based command and control, and compromised enterprise infrastructure, especially Microsoft Exchange and Outlook environments. High-confidence reporting identifies Glimpse as a DNS-tunneling RAT within that ecosystem rather than a commodity malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Glimpse: a new trojan based on PowerShell, dubbed BondUpdater by Palo Alto Networks ... Glimpse is a remote control tool that uses DNS tunneling.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In our next blog, we will examine the DNS Tunneling capability of Glimpse, which also has been linked to the OilRig/APT34 threat group.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
the attacker will create a scheduled task to execute the PowerShell script regularly... As a scheduled task, the vbs script is set to execute every 10 minutes.
The backdoor is very light weight and provides only the basic C2 capabilities such as download, upload, and execute.
Glimpse is a PowerShell script... The dataset includes both the agent that the actor would install on targeted systems and the server that would allow the actor to interact with compromised systems.
Reads contents from the command file, executes them as CMD commands
The attacker sends sensitive data to the controlled server using a DNS protocol through command and control... used two remote access Trojans ... for remote control of the target server by using a DNS protocol for communication. | Glimpse is a remote control tool that uses DNS tunneling.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Glimpse is referenced as another DNS-tunneling malware sample in the series; the conclusion notes it added a text mode using TXT records to increase throughput from the controller.
A PowerShell-based remote access trojan used for remote control via DNS tunneling. It uses an agent, panel, and server architecture, supports DNS A/TXT record communications, executes commands, uploads/downloads files, and uses scheduled tasks for persistence.
Named malware referenced as another DNS-tunneling sample linked to OilRig/APT34, but not analyzed in detail in this piece.
A tool exposed in leaked APT34 tooling and related to the updated BondUpdater tool.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.