Threat Advisory

Bondnet Utilizing Reverse RDP and Modified Tools for Persistent C2 Infrastructure

Threat: Malware
Threat Actor Name: Bondnet
Targeted Region: Global
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Bondnet, a notorious threat actor first analysed in 2017 and later in 2022, remains active and continues to evolve its attack strategies. Recently, the researcher discovered new activities involving Bondnet. By analyzing systems infected with Bondnet miners, Researcher found that since 2023, Bondnet has been configuring a reverse Remote Desktop Protocol (RDP) environment on high-performance bots to use them as Command and Control (C2) servers. This reverse RDP environment leverages specific conditions such as CPU specifications, network interface details, and system language settings to establish a robust and clandestine C2 infrastructure.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Bondnet, a notorious threat actor first analysed in 2017 and later in 2022, remains active and continues to evolve its attack strategies. Recently, the researcher discovered new activities involving Bondnet. By analyzing systems infected with Bondnet miners, Researcher found that since 2023, Bondnet has been configuring a reverse Remote Desktop Protocol (RDP) environment on high-performance bots to use them as Command and Control (C2) servers. This reverse RDP environment leverages specific conditions such as CPU specifications, network interface details, and system language settings to establish a robust and clandestine C2 infrastructure.[emaillocker id="1283"]

The Bondnet threat actor meticulously sets up the reverse RDP environment by first ensuring the target system meets specific conditions. These include adding an "adminxy" account if the CPU is an Intel i3, i5, i7, or i9 model, and the network interface is manufactured by Red Hat. Additionally, the system’s language must be Russian, Korean, English, or Japanese. Once these conditions are satisfied, and if the CPU core count exceeds 10, the threat actor downloads a reverse RDP program. They use a modified Fast Reverse Proxy (FRP) tool from GitHub, embedding their proxy server address, protocol, port, and token name for connection. Upon accessing the target system via RDP, the threat actor executes two programs: the Cloudflare tunneling client and an HTTP File Server (HFS) program. The tunneling client links a system port to a Cloudflare-mapped domain, and the HFS program, when executed, provides file server services to TCP port 4000. Despite environmental issues causing the HFS program to fail, similarities in UI between the target system's HFS and the threat actor’s C2 suggest the intention was to create a new C2 server.

The Bondnet threat actor's continuous adaptation and sophisticated techniques highlight their persistence and evolving threat landscape. Although the researcher team could not observe the complete conversion of the affected system to a C2 due to the HFS program's failure, various circumstantial evidence points to Bondnet's strategy of utilizing high-performance bots as C2 servers. The failed attempt led to a modification in the C2 setup, evidenced by changes in the C2 UI and the reappearance of malicious files. This activity underscores the importance of continuous monitoring and adaptation in cybersecurity defenses to counteract such persistent and evolving threats effectively.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1078 Valid Accounts
Execution T1569 System Services
Persistence T1136 Create Account
Defense Evasion T1027 Obfuscated Files or Information
T1036 Masquerading
Credential Access T1003 OS Credential Dumping
Discovery T1082 System Information Discovery
Command and Control T1071 Application Layer Protocol
T1219 Remote Access Software
T1090 Proxy
Impact T1496 Resource Hijacking
T1490 Inhibit System Recovery

REFERENCES:

The following reports contain further technical details:

https://asec.ahnlab.com/en/66662/

[/emaillocker]
crossmenu