Also known as: root access, a botnet, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
Bondnet is a threat actor that deploys backdoors and cryptocurrency miners. They use high-performance bots as C2 servers and configure reverse RDP environments on compromised systems. Bondnet has infected over 15,000 Windows server machines worldwide, primarily targeting Windows Server 2008 R2 systems. The botnet is used for mining cryptocurrencies like Monero, ByteCoin, RieCoin, and ZCash, potentially earning the operator thousands of dollars per day.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Bondnet is a financially motivated threat actor deploying backdoors and cryptocurrency miners, with a proven track record of infecting over 15,000 Windows servers globally. Their primary focus is on outdated Windows Server 2008 R2 systems, leveraging high-performance botnets for C2 operations and reverse RDP environments to maintain persistence. The actor generates significant revenue through large-scale cryptocurrency mining operations.
Goals & Targeting
Bondnet's primary objective is financial gain through large-scale cryptocurrency mining, with a particular focus on resource-rich, outdated Windows systems. The actor targets Windows Server 2008 R2 due to its widespread deployment in legacy environments and limited security updates, making it a soft target for exploitation. By deploying high-performance bots and configuring reverse RDP, Bondnet ensures robust operational control and persistence, allowing it to maintain access to victim networks for extended periods. The group's targeting profile suggests a preference for unpatched systems, potentially in industries with delayed patching processes, such as small-to-medium enterprises, government agencies, and unmanaged enterprise environments.
Enhanced Description
Bondnet is a threat actor actively deploying backdoors and cryptocurrency mining malware, targeting vulnerable systems to exploit for financial gain. The group utilizes high-performance botnets as C2 infrastructure, enabling centralized control over a vast network of compromised systems. By configuring reverse RDP environments on infected machines, Bondnet ensures long-term persistence and covert access to victim networks. The actor has demonstrated a preference for Windows Server 2008 R2 systems, which remain prevalent in legacy environments due to their end-of-life status and inherent vulnerabilities. This targeting strategy highlights the actor's focus on exploiting unpatched systems, which are often easier to compromise and maintain access to over extended periods. The scale of Bondnet's operations is significant, with over 15,000 Windows servers infected globally, including systems used for mining cryptocurrencies such as Monero, ByteCoin, RieCoin, and ZCash. The financial impact of these operations is substantial, with potential daily earnings in the thousands of dollars for the actor's operators. This activity aligns with a broader trend in cybercrime where threat groups leverage cryptocurrency mining for sustained revenue generation, often using legitimate infrastructure to evade detection.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Bondnet maintains a low operational tempo with a focus on long-term persistence and resource exploitation. Their campaigns primarily target unpatched systems, leveraging outdated software vulnerabilities to deploy mining malware. The group's use of high-performance botnets as C2 infrastructure suggests a structured operational model aimed at scalability. Notable past operations include the widespread infection of Windows Server 2008 R2 systems, with no reported public attribution or high-profile breaches directly linked to their activities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate to high confidence in the described activities based on the large-scale infection statistics and technical indicators. However, limited public attribution and lack of detailed TTPs in the original report create gaps in full operational understanding. Further analysis of specific IOCs and network traffic patterns would strengthen attribution and mitigate uncertainty.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics