Malware.View on attack.mitre.org
BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group. It is set to run when the system boots and includes functionality to check, upload, and register plug-ins that can further enhance its capabilities.
| Technique | Procedure example |
|---|---|
| T1071.001 Web Protocols |
BUBBLEWRAP can communicate using HTTP or HTTPS. |
| T1082 System Information Discovery |
BUBBLEWRAP collects system information, including the operating system version and hostname. |
| T1095 Non-Application Layer Protocol |
BUBBLEWRAP can communicate using SOCKS. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.