September 24, 2018 By Shane Schick < 1 min read

The OilRig threat group launched an attack involving the BONDUPDATER Trojan malware against a high-ranking government office in the Middle East.

According to Palo Alto Networks’ Unit 42, the threat group sent a series of spear phishing emails with a blank subject line to government workers in the region last month. Anyone who opened the attachment risked activating the latest version of BONDUPDATER, which offers backdoor functionality that lets threat actors execute commands and download files on infected machines.

OilRig, which has been active for at least two years, had previously used the Trojan malware in similar attacks against Middle Eastern governments.

What’s New in This Version of BONDUPDATER?

BONDUPDATER was first spotted in November 2017 and is based on Microsoft’s PowerShell. In the most recent attack, however, researchers found that the spear phishing emails contained a Word document with a macro that installed the Trojan malware. The process involved creating a series of files on the victim’s system and then gaining persistence by dropping a script that scheduled a task to execute every minute.

This version of BONDUPDATER used TXT records to communicate with the command-and-control (C&C) server as well as the Domain Name System (DNS) A records, which it received by using a DNS tunneling protocol. This follows a pattern in which OilRig doesn’t always develop new tools, but simply saves development time by building on Trojan malware that’s already part of its arsenal.

Avoid Trojan Malware With UBA and IAM

In a recent podcast, IBM experts recommended layering on user behavior analytics (UBA) with identity and access management (IAM), which can make it easier to detect when employees exhibit potentially risky behaviors. This should be coupled with ongoing efforts to educate users about phishing schemes.

Source: Palo Alto Networks

More from

2024 trends: Were they accurate?

4 min read - The new year always kicks off with a flood of prediction articles; then, 12 months later, our newsfeed is filled with wrap-up articles. But we are often left to wonder if experts got it right in January about how the year would unfold. As we close out 2024, let’s take a moment to go back and see if the crystal balls were working about how the year would play out in cybersecurity.Here are five trends that were often predicted for…

Ransomware attack on Rhode Island health system exposes data of hundreds of thousands

3 min read - Rhode Island is grappling with the fallout of a significant ransomware attack that has compromised the personal information of hundreds of thousands of residents enrolled in the state’s health and social services programs. Officials confirmed the attack on the RIBridges system—the state’s central platform for benefits like Medicaid and SNAP—after hackers infiltrated the system on December 5, planting malicious software and threatening to release sensitive data unless a ransom is paid. Governor Dan McKee, addressing the media, called the attack…

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today