BUGJUICE

BUGJUICEBUGJUICE

Description

BUGJUICE is a backdoor that is executed by launching a benign file and then hijacking the search order to load a malicious dll into it. That malicious dll then loads encrypted shellcode from the binary, which is decrypted and runs the final BUGJUICE payload. BUGJUICE defaults to TCP using a custom binary protocol to communicate with the C2, but can also use HTTP and HTTPs if directed by the C2. It has the capability to find files, enumerate drives, exfiltrate data, take screenshots and provide a reverse shell.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
BugWare
Software
BumbleBee
Software
SNUGRIDE
Software
Backdoor.Tinybaron
Software
Backdoor.Dripion
Software
Adwind
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.