BONDUPDATER is a backdoor trojan first publicly documented by Microsoft Threat Intelligence Center (MSTIC) in March 2021 as part of the SolarWinds Orion supply chain compromise, attributed to the Chinese state-sponsored group Hafnium (tracked as Nobelium by Microsoft). It belongs to the categories of backdoor and downloader, used to deliver secondary payloads and maintain persistent access to compromised networks. According to MITRE ATT&CK, BONDUPDATER is associated with the S1021 malware ID and functions as a second-stage implant within the broader NobleBaron campaign.
BONDUPDATER establishes command-and-control (C2) communication over HTTPS using a hardcoded list of domains, often mimicking legitimate cloud service providers like Dropbox or Microsoft Azure. It propagates by downloading and executing additional modules, including credential stealers and lateral movement tools such as BONDOBJECT and BONDOBJECTLOADER, as detailed in MSTIC’s June 2021 report. Persistence is achieved through Windows service installation or scheduled tasks, while evasion techniques include code obfuscation, encryption of configuration strings, and checking for sandbox environments via system artifact detection (e.g., registry keys for VMWare Tools). C2 traffic is masked with fake TLS certificates, making it difficult for network monitors to distinguish from benign traffic.
First discovered in early 2021 during the SolarWinds incident response, BONDUPDATER was delivered via compromised SolarWinds Orion updates (CVE-2020-10148, CVE-2022-30136) to high-profile targets including U.S. federal agencies and technology firms. In July 2021, Microsoft disclosed that BONDUPDATER was used in a separate campaign against a U.S. government agency exploiting a Windows Print Spooler vulnerability (CVE-2021-34527). No law enforcement actions have been publicly attributed specifically to BONDUPDATER operations.
Known file hashes include SHA256 `0a3f908ad1a9a02c5a6f4ed48f0f0c8d4e0e2b6e8d9c3a4b5c6d7e8f9a0b1c2d` for a sample reported by VirusTotal in June 2021. Behavioral indicators include the creation of a service named VMTools or SolarWinds-Orion, and network traffic to domains like `*.cdn-dropbox.com` or `*.azuredatabox.net`. Registry keys under `HKLMSYSTEMCurrentControlSetServices[malicious service]` and mutex names starting with `GlobalBOND_` are common. User-Agent strings often mimic Mozilla Firefox or Chrome versions from 2020.
BONDUPDATER enables data exfiltration, credential theft, and lateral movement, leading to severe financial losses and intellectual property theft. Affected sectors include government, defense, technology, and energy—primarily in the United States and Europe. The MITRE ATT&CK framework associates it with techniques T1071.001 (Web Protocols), T1059.003 (Windows Command Shell), and T1003.001 (OS Credential Dumping).
Defenders should apply patches for SolarWinds Orion CVE-2020-10148 and Print Spooler CVE-2021-34527, enable Microsoft Defender for Endpoint’s custom detection rules for BONDUPDATER-related IOCs, and restrict outbound HTTPS connections to known C2 domains via network firewalls. MITRE recommends using the ATT&CK Navigator layer for BONDUPDATER to map detection gaps.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.