BLUERABBIT
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Techniques & procedures
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
3 techniques
Execution
BLUERABBIT checks the registry key HKCU\Software\OneDrive\Environment to track its execution count. If this key does not exist, the malware assumes it is running for the first time and executes a PowerShell command to establish persistence as a scheduled task named “OneDrive Update,” deliberately impersonating a legitimate Microsoft service.
Persistence
2 techniques
Persistence
BLUERABBIT checks the registry key HKCU\Software\OneDrive\Environment to track its execution count. If this key does not exist, the malware assumes it is running for the first time and executes a PowerShell command to establish persistence as a scheduled task named “OneDrive Update,” deliberately impersonating a legitimate Microsoft service.
The following registry modifications are made to disable automatic reboot and system recovery | Upon execution, BLUERABBIT checks the registry key HKCU\Software\OneDrive\Environment to track its execution count... The path for files staged for exfiltration is written to the registry key HKCU\Software\OneDrive\ProfileConfig.
Privilege Escalation
1 technique
Privilege Escalation
BLUERABBIT checks the registry key HKCU\Software\OneDrive\Environment to track its execution count. If this key does not exist, the malware assumes it is running for the first time and executes a PowerShell command to establish persistence as a scheduled task named “OneDrive Update,” deliberately impersonating a legitimate Microsoft service.
Stealth
1 technique
Stealth
Creates “OneDrive Update” scheduled task... deliberately impersonating a legitimate Microsoft service. When launching the VNC remote desktop module, BLUERABBIT creates a firewall rule under the deceptive name Microsoft.Windows.CloudExperienceHost to blend in with legitimate Windows components.
Defense Impairment
1 technique
Defense Impairment
The following registry modifications are made to disable automatic reboot and system recovery | Upon execution, BLUERABBIT checks the registry key HKCU\Software\OneDrive\Environment to track its execution count... The path for files staged for exfiltration is written to the registry key HKCU\Software\OneDrive\ProfileConfig.
Discovery
4 techniques
Discovery
Surveillance Screenshot capture, screen recording, process and Windows service enumeration and management
Surveillance Screenshot capture, screen recording, process and Windows service enumeration and management
Collection
3 techniques
Collection
Command and Control
2 techniques
Command and Control
AMQP RabbitMQ Primary tasking channel. Malware declares a queue named after the victim device; consumer tag is the full path to the malicious executable. Task IDs received as JSON. | BLUERABBIT’s main execution loop follows the sequence MessageReader, ProcessTask, UpdateRedis, relying on enterprise messaging and database protocols rather than conventional HTTP-based C2.
Exfiltration
1 technique
Exfiltration
Impact
3 techniques
Impact
File Encryption Encrypts files across all logical drives with .candy extension; replaces desktop wallpaper with AI-generated “High-Alert” image
IOCs tracked for this family
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based Windows backdoor that provides persistent access, disguises C2 via RabbitMQ, stores task results in Redis, exfiltrates stolen data through MinIO, can encrypt files with a .candy extension, and includes multiple disk-wiping capabilities designed to prevent recovery.
A Golang-based full-featured backdoor that provides remote access, system profiling, VNC-based control, file exfiltration, file encryption using the .candy extension, and two disk-wiping modules capable of permanently rendering systems unrecoverable. It uses RabbitMQ for tasking, Redis for state management, and MinIO for exfiltration.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.