September 24, 2018 By Shane Schick < 1 min read

The OilRig threat group launched an attack involving the BONDUPDATER Trojan malware against a high-ranking government office in the Middle East.

According to Palo Alto Networks’ Unit 42, the threat group sent a series of spear phishing emails with a blank subject line to government workers in the region last month. Anyone who opened the attachment risked activating the latest version of BONDUPDATER, which offers backdoor functionality that lets threat actors execute commands and download files on infected machines.

OilRig, which has been active for at least two years, had previously used the Trojan malware in similar attacks against Middle Eastern governments.

What’s New in This Version of BONDUPDATER?

BONDUPDATER was first spotted in November 2017 and is based on Microsoft’s PowerShell. In the most recent attack, however, researchers found that the spear phishing emails contained a Word document with a macro that installed the Trojan malware. The process involved creating a series of files on the victim’s system and then gaining persistence by dropping a script that scheduled a task to execute every minute.

This version of BONDUPDATER used TXT records to communicate with the command-and-control (C&C) server as well as the Domain Name System (DNS) A records, which it received by using a DNS tunneling protocol. This follows a pattern in which OilRig doesn’t always develop new tools, but simply saves development time by building on Trojan malware that’s already part of its arsenal.

Avoid Trojan Malware With UBA and IAM

In a recent podcast, IBM experts recommended layering on user behavior analytics (UBA) with identity and access management (IAM), which can make it easier to detect when employees exhibit potentially risky behaviors. This should be coupled with ongoing efforts to educate users about phishing schemes.

Source: Palo Alto Networks

More from

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

SoaPy: Stealthy enumeration of Active Directory environments through ADWS

10 min read - Introduction Over time, both targeted and large-scale enumeration of Active Directory (AD) environments have become increasingly detected due to modern defensive solutions. During our internship at X-Force Red this past summer, we noticed FalconForce’s SOAPHound was becoming popular for enumerating Active Directory environments. This tool brought a new perspective to Active Directory enumeration by performing collection via Active Directory Web Services (ADWS) instead of directly through Lightweight Directory Access Protocol (LDAP) as other AD enumeration tools had in the past.…

Smoltalk: RCE in open source agents

26 min read - Big shoutout to Hugging Face and the smolagents team for their cooperation and quick turnaround for a fix! Introduction Recently, I have been working on a side project to automate some pentest reconnaissance with AI agents. Just after I started this project, Hugging Face announced the release of smolagents, a lightweight framework for building AI agents that implements the methodology described in the ReAct paper, emphasizing reasoning through iterative decision-making. Interestingly, smolagents enables agents to reason and act by generating…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today