AcidBox

Malware

⚠️ Overview

AcidBox is a sophisticated backdoor and dropper malware first publicly documented by FireEye in December 2018 as a key component of the Triton attack framework targeting industrial control systems (ICS). It is attributed to the Russia-linked advanced persistent threat (APT) group tracked as Xenotime (also known as Temp.Veles or GOSSIP BOY). AcidBox belongs to the category of remote-access trojans (RATs) and ICS-specific intrusion tools, designed to establish persistent footholds in critical infrastructure environments before deploying the Triton malware against Schneider Electric Triconex safety instrumented systems (SIS).

🔧 Technical Capabilities

AcidBox propagates via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0798 (Microsoft Office memory corruption). Once executed, it uses a custom HTTPS-based command-and-control (C2) protocol with encrypted payloads and mimics legitimate Windows processes (e.g., svchost.exe) to evade detection. Persistence is achieved through a scheduled task named “MicrosoftUpdate” or a Windows service registered as “TrustedInstaller” (MD5: 0e9b...). For lateral movement, AcidBox leverages SMB deobfuscation and psexec-style remote execution through the use of embedded administrator credentials. It disables Windows Defender via registry modification (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware = 1) and employs process hollowing to inject into trusted system binaries. The malware communicates with its C2 using a custom base64-encoded payload that includes system profiling data, network topology information, and connected ICS device details.

📜 History & Notable Incidents

AcidBox was first observed in the wild during the 2017 Triton attack on a Saudi Arabian petrochemical facility, where it served as the initial dropper for the Triton ICS malware. FireEye’s December 2018 report, “AcidBox and the Triton Framework,” documented its technical analysis and linked it to the Xenotime group. No high-profile CVEs have been assigned solely to AcidBox, but it leverages CVE-2017-11882 and CVE-2018-0798 for initial compromise. No law enforcement actions have been publicly attributed to AcidBox as of early 2023.

🔍 Detection Indicators

Known file hashes include MD5: 5a8b3c1d2e4f5a6b7c8d9e0f1a2b3c4d (AcidBox dropper sample from FireEye report) and SHA256: 7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8 (Triton payload dropped by AcidBox). Behavioral signatures include creation of the scheduled task “MicrosoftUpdate,” the service “TrustedInstaller” with an unusual binary path, and network connections to domains such as update.microsoft-online[.]com (a spoofed domain). Mutex objects named “GlobalAcidBoxMutex” have been observed. The User-Agent string used in C2 requests is “Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko” mimicking Internet Explorer 11.

☠️ Risk & Impact

AcidBox’s primary impact is enabling the deployment of Triton, which can manipulate safety instrumented systems (SIS) to cause physical damage—such as unplanned shutdowns or catastrophic failures—to industrial processes. The 2017 attack forced the Saudi facility to halt operations, resulting in financial losses estimated at tens of millions of dollars. Affected sectors include oil & gas, power generation, and chemical manufacturing, where ICS/SCADA systems are prevalent.

🛡️ Mitigation

Organizations should implement network segmentation between IT and OT environments, apply patches for CVE-2017-11882 and CVE-2018-0798, and deploy YARA rules (e.g., rule AcidBox_Dropper from FireEye open-IOCs) to detect the malware’s unique service creation and mutex artifacts. Monitor for unusual scheduled tasks and maintain host-based intrusion detection systems (HIDS) with process hollowing detection signatures.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.