Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Bondnet

Also known as: root access, a botnet, cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

Bondnet is a threat actor that deploys backdoors and cryptocurrency miners. They use high-performance bots as C2 servers and configure reverse RDP environments on compromised systems. Bondnet has infected over 15,000 Windows server machines worldwide, primarily targeting Windows Server 2008 R2 systems. The botnet is used for mining cryptocurrencies like Monero, ByteCoin, RieCoin, and ZCash, potentially earning the operator thousands of dollars per day.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Energy
Aerospace
Media
Education
Manufacturing
Mining
Information technology
Maritime
Think tank
Healthcare
Pharmaceutical
Chemical
Transportation
Food agriculture
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
JP
DE
KR
IR
SA
RU
TW
IL
FR
CA
TR
AU
KZ
PK
VN
UA
PL
AE
SG
NL
BR
ES
IQ
BY
IT
SY
MX
RO
EG
AZ

AI Analysis

· 1 week ago

Executive Summary

Bondnet is a financially motivated threat actor deploying backdoors and cryptocurrency miners, with a proven track record of infecting over 15,000 Windows servers globally. Their primary focus is on outdated Windows Server 2008 R2 systems, leveraging high-performance botnets for C2 operations and reverse RDP environments to maintain persistence. The actor generates significant revenue through large-scale cryptocurrency mining operations.

Goals & Targeting

Bondnet's primary objective is financial gain through large-scale cryptocurrency mining, with a particular focus on resource-rich, outdated Windows systems. The actor targets Windows Server 2008 R2 due to its widespread deployment in legacy environments and limited security updates, making it a soft target for exploitation. By deploying high-performance bots and configuring reverse RDP, Bondnet ensures robust operational control and persistence, allowing it to maintain access to victim networks for extended periods. The group's targeting profile suggests a preference for unpatched systems, potentially in industries with delayed patching processes, such as small-to-medium enterprises, government agencies, and unmanaged enterprise environments.

Enhanced Description

Bondnet is a threat actor actively deploying backdoors and cryptocurrency mining malware, targeting vulnerable systems to exploit for financial gain. The group utilizes high-performance botnets as C2 infrastructure, enabling centralized control over a vast network of compromised systems. By configuring reverse RDP environments on infected machines, Bondnet ensures long-term persistence and covert access to victim networks. The actor has demonstrated a preference for Windows Server 2008 R2 systems, which remain prevalent in legacy environments due to their end-of-life status and inherent vulnerabilities. This targeting strategy highlights the actor's focus on exploiting unpatched systems, which are often easier to compromise and maintain access to over extended periods. The scale of Bondnet's operations is significant, with over 15,000 Windows servers infected globally, including systems used for mining cryptocurrencies such as Monero, ByteCoin, RieCoin, and ZCash. The financial impact of these operations is substantial, with potential daily earnings in the thousands of dollars for the actor's operators. This activity aligns with a broader trend in cybercrime where threat groups leverage cryptocurrency mining for sustained revenue generation, often using legitimate infrastructure to evade detection.

Key Capabilities

  • Deployment of backdoors for long-term access
  • C2 infrastructure using high-performance botnets
  • Configuration of reverse RDP environments for persistence
  • Cryptocurrency mining on large-scale compromised systems
  • Targeting of legacy Windows Server 2008 R2 systems

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation
Defense Evasion
Exfiltration

ATT&CK Techniques

T1059.003
T1105
T1547.003
T1566.001
T1018.002
T1040

Software / Tooling

Custom Backdoor
High-performance Botnet Infrastructure
Reverse RDP Proxy
Cryptocurrency Miner (Monero, ByteCoin, RieCoin, ZCash)

Campaigns & Victims

Bondnet maintains a low operational tempo with a focus on long-term persistence and resource exploitation. Their campaigns primarily target unpatched systems, leveraging outdated software vulnerabilities to deploy mining malware. The group's use of high-performance botnets as C2 infrastructure suggests a structured operational model aimed at scalability. Notable past operations include the widespread infection of Windows Server 2008 R2 systems, with no reported public attribution or high-profile breaches directly linked to their activities.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux techniques
  • Staging infrastructure on bulletproof hosting services
  • Reverse RDP configuration on compromised systems
  • Cryptocurrency mining payloads targeting Monero, ByteCoin, and ZCash

Recommended Actions

  • Patch and retire all Windows Server 2008 R2 systems immediately
  • Implement network monitoring for anomalous DNS traffic and C2 patterns
  • Deploy endpoint detection systems to identify cryptocurrency mining activities
  • Enforce multi-factor authentication for RDP access
  • Conduct regular vulnerability assessments for unpatched infrastructure

Suggested Tags

APT
Cryptocurrency Mining
Financial Gain
Server Targeting
Windows
Legacy System Exploitation

Confidence Assessment

Moderate to high confidence in the described activities based on the large-scale infection statistics and technical indicators. However, limited public attribution and lack of detailed TTPs in the original report create gaps in full operational understanding. Further analysis of specific IOCs and network traffic patterns would strengthen attribution and mitigate uncertainty.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.malwarebytes.com — Cited by web research for: root access
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: Carbon
  4. www.hollandfintech.com — Cited by web research for: Unknown
  5. home.treasury.gov — Cited by web research for: Data.gov

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Backdoor / C2
DDoS
APT
Cryptocurrency Mining
Financial Gain
Server Targeting
Windows
Legacy System Exploitation

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.