EXECUTIVE SUMMARY
Bondnet, a notorious threat actor first analysed in 2017 and later in 2022, remains active and continues to evolve its attack strategies. Recently, the researcher discovered new activities involving Bondnet. By analyzing systems infected with Bondnet miners, Researcher found that since 2023, Bondnet has been configuring a reverse Remote Desktop Protocol (RDP) environment on high-performance bots to use them as Command and Control (C2) servers. This reverse RDP environment leverages specific conditions such as CPU specifications, network interface details, and system language settings to establish a robust and clandestine C2 infrastructure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Bondnet, a notorious threat actor first analysed in 2017 and later in 2022, remains active and continues to evolve its attack strategies. Recently, the researcher discovered new activities involving Bondnet. By analyzing systems infected with Bondnet miners, Researcher found that since 2023, Bondnet has been configuring a reverse Remote Desktop Protocol (RDP) environment on high-performance bots to use them as Command and Control (C2) servers. This reverse RDP environment leverages specific conditions such as CPU specifications, network interface details, and system language settings to establish a robust and clandestine C2 infrastructure.[emaillocker id="1283"]
The Bondnet threat actor meticulously sets up the reverse RDP environment by first ensuring the target system meets specific conditions. These include adding an "adminxy" account if the CPU is an Intel i3, i5, i7, or i9 model, and the network interface is manufactured by Red Hat. Additionally, the system’s language must be Russian, Korean, English, or Japanese. Once these conditions are satisfied, and if the CPU core count exceeds 10, the threat actor downloads a reverse RDP program. They use a modified Fast Reverse Proxy (FRP) tool from GitHub, embedding their proxy server address, protocol, port, and token name for connection. Upon accessing the target system via RDP, the threat actor executes two programs: the Cloudflare tunneling client and an HTTP File Server (HFS) program. The tunneling client links a system port to a Cloudflare-mapped domain, and the HFS program, when executed, provides file server services to TCP port 4000. Despite environmental issues causing the HFS program to fail, similarities in UI between the target system's HFS and the threat actor’s C2 suggest the intention was to create a new C2 server.
The Bondnet threat actor's continuous adaptation and sophisticated techniques highlight their persistence and evolving threat landscape. Although the researcher team could not observe the complete conversion of the affected system to a C2 due to the HFS program's failure, various circumstantial evidence points to Bondnet's strategy of utilizing high-performance bots as C2 servers. The failed attempt led to a modification in the C2 setup, evidenced by changes in the C2 UI and the reappearance of malicious files. This activity underscores the importance of continuous monitoring and adaptation in cybersecurity defenses to counteract such persistent and evolving threats effectively.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1078 | Valid Accounts |
| Execution | T1569 | System Services |
| Persistence | T1136 | Create Account |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1036 | Masquerading | |
| Credential Access | T1003 | OS Credential Dumping |
| Discovery | T1082 | System Information Discovery |
| Command and Control | T1071 | Application Layer Protocol |
| T1219 | Remote Access Software | |
| T1090 | Proxy | |
| Impact | T1496 | Resource Hijacking |
| T1490 | Inhibit System Recovery |
REFERENCES:
The following reports contain further technical details:
[/emaillocker]