logo

Bondnet Using Miner Bots as C2

ID: f72b8fc8-39a9-586c-ada8-da37df4c8d77

STIX ID: report--f72b8fc8-39a9-586c-ada8-da37df4c8d77

Feed Name: ASEC

Threat Score
72/100

Date Published: 2024-06-12

Date Updated: 2026-04-26

Author: gwonwanglee1

...
...

ASEC analysis confirms the Bondnet actor remains active and has been configuring reverse RDP environments on high-performance infected hosts since 2023 by adding privileged accounts, modifying and using FRP proxies, deploying a Cloudflare tunneling client and attempting to run an HFS-based C2; the report documents miner/backdoor activity, related detections, and provides MD5s, URLs, domains, and IP indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.