logo

BITS and Bytes: Analyzing BITSLOTH, a newly identified backdoor

ID: a366ef14-afd9-5c56-b9a5-fd1940c33ca1

STIX ID: report--a366ef14-afd9-5c56-b9a5-fd1940c33ca1

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2024-08-01

Date Updated: 2026-04-27

...
...

Elastic Security Labs describes BITSLOTH, a previously undocumented Windows backdoor used in an intrusion (REF8747) against a South American foreign ministry; the malware abuses the Background Intelligent Transfer Service (BITS) for stealthy C2 and persistence, implements 35 command handlers (discovery, execution, file upload/download, keylogging, screenshots), includes observable IOCs (file hashes, C2 IPs, BITS job names), and shows development history dating back to 2021.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.