BITS Jobs

T1197

Technique.View on attack.mitre.org

About this technique

Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth, asynchronous file transfer mechanism exposed through Component Object Model (COM). BITS is commonly used by updaters, messengers, and other applications preferred to operate in the background (using available idle bandwidth) without interrupting other networked applications. File transfer tasks are implemented as BITS jobs, which contain a queue of one or more file operations.

The interface to create and manage BITS jobs is accessible through PowerShell and the BITSAdmin tool.

Adversaries may abuse BITS to download (e.g. Ingress Tool Transfer), execute, and even clean up after running malicious code (e.g. Indicator Removal). BITS tasks are self-contained in the BITS job database, without new files or registry modifications, and often permitted by host firewalls. BITS enabled execution may also enable persistence by creating long-standing jobs (the default maximum lifetime is 90 days and extendable) or invoking an arbitrary program when a job completes or errors (including after system reboots).

BITS upload functionalities can also be used to perform Exfiltration Over Alternative Protocol.

Detection rules21

Rules on DetectionCode tagged with T1197.

Sigma16

Splunk5

RuleTypeRiskData source
BITS Job PersistenceTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
BITSAdmin Download FileTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Cisco NVM - Curl Execution With Insecure FlagsAnomalyNULLCisco Network Visibility Module Flow Data
Cisco NVM - Suspicious Download From File Sharing WebsiteAnomalyNULLCisco Network Visibility Module Flow Data
PowerShell Start-BitsTransferTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups5

Software8

Campaigns0

None recorded.

Procedure examples13

Groups5

Used byProcedure example
GroupAPT39

APT39 has used the BITS protocol to exfiltrate stolen data from a compromised host.

GroupAPT41

APT41 used BITSAdmin to download and install payloads.

GroupLeviathan

Leviathan has used BITSAdmin to download additional tools.

GroupPatchwork

Patchwork has used BITS jobs to download malicious payloads.

GroupWizard Spider

Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine.

Software8

Used byProcedure example
MalwareBazar

Bazar has been downloaded via Windows BITS functionality.

ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to launch a malicious process.

MalwareCobalt Strike

Cobalt Strike can download a hosted "beacon" payload using BITSAdmin.

MalwareEgregor

Egregor has used BITSadmin to download and execute malicious DLLs.

MalwareJPIN

A JPIN variant downloads the backdoor payload via the BITS service.

MalwareMarkiRAT

MarkiRAT can use BITS Utility to connect with the C2 server.

MalwareProLock

ProLock can use BITS jobs to download its malicious payload.

MalwareUBoatRAT

UBoatRAT takes advantage of the /SetNotifyCmdLine option in BITSAdmin to ensure it stays running on a system to maintain persistence.

References7

  1. CTU BITS Malware June 2016 Open source
    Counter Threat Unit Research Team. (2016, June 6). Malware Lingers with BITS. Retrieved January 12, 2018.
  2. Microsoft BITS Open source
    Microsoft. (n.d.). Background Intelligent Transfer Service. Retrieved January 12, 2018.
  3. Microsoft BITSAdmin Open source
    Microsoft. (n.d.). BITSAdmin Tool. Retrieved January 12, 2018.
  4. Microsoft COM Open source
    Microsoft. (n.d.). Component Object Model (COM). Retrieved November 22, 2017.
  5. Mondok Windows PiggyBack BITS May 2007 Open source
    Mondok, M. (2007, May 11). Malware piggybacks on Windows’ Background Intelligent Transfer Service. Retrieved January 12, 2018.
  6. PaloAlto UBoatRAT Nov 2017 Open source
    Hayashi, K. (2017, November 28). UBoatRAT Navigates East Asia. Retrieved January 12, 2018.
  7. Symantec BITS May 2007 Open source
    Florio, E. (2007, May 9). Malware Update with Windows Update. Retrieved January 12, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.