BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group. It is set to run when the system boots and includes functionality to check, upload, and register plug-ins that can further enhance its capabilities. [1]
| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1071 | .001 | 应用层协议: Web Protocols |
BUBBLEWRAP can communicate using HTTP or HTTPS.[1] |
| Enterprise | T1082 | 系统信息发现 |
BUBBLEWRAP collects system information, including the operating system version and hostname.[1] |
|
| Enterprise | T1095 | 非应用层协议 |
BUBBLEWRAP can communicate using SOCKS.[1] |
|