MINEBRIDGE is a Windows remote-access malware family used as a backdoor and commonly associated with financially motivated intrusion activity linked with TA505. It has been delivered in phishing campaigns using macro-enabled Microsoft Word documents disguised as job resumes or other employment-themed lures, including targeting security and threat-intelligence personnel. Observed infection chains abuse living-off-the-land utilities to retrieve and decode an initial payload, then use a self-extracting archive and DLL sideloading through a legitimate TeamViewer binary to launch the malware.
Once installed, MINEBRIDGE provides broad remote control over an আক্রান্ত system. Reported capabilities include downloading and executing additional payloads, running shell commands, loading DLLs, updating itself, terminating or restarting itself, killing processes, shutting down or rebooting the host, and gathering host and user information. Variants have established persistence via a startup shortcut and have used multiple worker threads for command-and-control, persistence maintenance, and user-interface suppression. MINEBRIDGE has also been observed hooking Windows APIs to reduce visible signs of execution and to capture TeamViewer-generated identifiers and passwords, enabling theft of remote-access credentials and abuse of TeamViewer functionality. Reported functionality also includes process listing, process elevation, and control over TeamViewer microphone features.
Operationally, MINEBRIDGE communicates with hardcoded command-and-control infrastructure over web protocols, including HTTPS, and exfiltrates victim metadata over the same channel. Collected data has included system identifiers, usernames, computer names, operating system details, and TeamViewer access information. Some reporting describes custom TeamViewer-loading variants or loaders as part of the broader MINEBRIDGE tooling cluster, reflecting its recurring use of legitimate remote-administration software as execution cover and access enablement.
MINEBRIDGE has been reported in campaigns against South Korean organizations and in broader TA505-linked phishing operations. The malware’s tradecraft is notable for combining social-engineering lures, LOLBin abuse, software packing, and DLL sideloading to evade detection while establishing durable remote access on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In Jan 2021, Zscaler ThreatLabZ discovered new instances of the MINEBRIDGE remote-access Trojan (RAT) embedded in macro-based Word document files crafted to look like valid job resumes (CVs).
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The deobfuscated command executed by the macro, shown below, uses the finger command to download a Base64 encoded certificate from a remote server and saves it as %AppData%\vUCooUr.
When a victim clicks on the 'Enabled Editing' or 'Enable Content' buttons, a password protected macro will be executed to download the MineBridge malware and run it.
TA505 has been leveraging the Get2 loader using the same crypter since at least September 2019... the crypter has remained the same with a few modifications every few months.
uses the finger command to download a Base64 encoded certificate from a remote server... The certificate retrieved via the finger command is a base64 encoded malware downloader malware executable.
Collectively, the two C2 methods support commands for ... self-deletion and updating
In September, we reported that security researchers discovered a way to use Finger as a LoLBin to download malware from a remote computer or exfiltrate data.
The loader performs a checkin to the C2 with a hardcoded User-Agent as well. POST /~bv0j3irngskdn13/g4t3_indata.php HTTP/1.1
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A remote access trojan that is delivered via macro-enabled Word documents, abuses a vulnerable TeamViewer binary for DLL side-loading, establishes persistence via a startup LNK, hooks APIs to hide execution and capture TeamViewer credentials, downloads additional payloads via BITS, and communicates with C2 servers over HTTPS to exfiltrate host and user data.
A custom loader/backdoor that deploys TeamViewer and communicates with C2 using hardcoded commands and infrastructure; the article links it to the same crypter overlap and TA505 reporting.
MineBridge is a backdoor delivered through phishing Word documents with malicious macros. The infection chain uses the Windows Finger command to fetch a Base64-encoded payload, decodes it with certutil, then downloads TeamViewer and sideloads a malicious DLL via DLL hijacking. Once active, it gives attackers full access, including downloading and executing payloads, running shell commands, listing processes, elevating privileges, rebooting or shutting down systems, self-updating or deleting, gathering UAC information, and turning TeamViewer's microphone on or off.
Ransomware referenced as part of Hive0065/TA505 operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.