S0360Windows
S0360BONDUPDATER
Platforms
1
ATT&CK
14.1
References
3
Description
[BONDUPDATER](https://attack.mitre.org/software/S0360) is a PowerShell backdoor used by [OilRig](https://attack.mitre.org/groups/G0049). It was first observed in November 2017 during targeting of a Middle Eastern government organization, and an updated version was observed in August 2018 being used to target a government organization with spearphishing emails.(Citation: FireEye APT34 Dec 2017)(Citation: Palo Alto OilRig Sep 2018)
Platforms· 1
Windows
Attributed to1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Group | OilRigg0049 | 100% | live |
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.