Bondnet Using Miner Bots as C2
ID: f72b8fc8-39a9-586c-ada8-da37df4c8d77
STIX ID: report--f72b8fc8-39a9-586c-ada8-da37df4c8d77
Feed Name: ASEC
Threat Score
ASEC analysis confirms the Bondnet actor remains active and has been configuring reverse RDP environments on high-performance infected hosts since 2023 by adding privileged accounts, modifying and using FRP proxies, deploying a Cloudflare tunneling client and attempting to run an HFS-based C2; the report documents miner/backdoor activity, related detections, and provides MD5s, URLs, domains, and IP indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
