ATT&CKSoftwareBUBBLEWRAP

BUBBLEWRAP

S0043

Malware.View on attack.mitre.org

About this malware

BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group. It is set to run when the system boots and includes functionality to check, upload, and register plug-ins that can further enhance its capabilities.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1071.001
Web Protocols

BUBBLEWRAP can communicate using HTTP or HTTPS.

T1082
System Information Discovery

BUBBLEWRAP collects system information, including the operating system version and hostname.

T1095
Non-Application Layer Protocol

BUBBLEWRAP can communicate using SOCKS.

Groups that use it1

Campaigns0

None recorded.

References1

  1. FireEye admin@338 Open source
    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.