APT34's Enhanced Cyber Espionage: BONDUPDATER and POWRUNER Malware Variants Unveiled
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Backdoor,RAT
- Attack Complexity: High
- Threat Risk: High Impact/Low Probability
Threat Overview
Booz Allen DarkLabs' Threat Hunt team pivoted from FireEye's December 2017 APT34 report to discover three previously unreported BONDUPDATER/POWRUNER variants, then extended that work using a ClearSky tip to find two more, yielding seven total malware samples linked to APT34 operations. All variants follow the same execution chain: a dropper (.exe) creates and runs rUpdateChecker.ps1 in a staging directory (C:\ProgramData\Windows\Microsoft\java\ or C:\Users\Public\Java), which creates a VBScript and a scheduled task to run the script every minute. The VBScript deploys POWRUNER — a PowerShell backdoor for arbitrary command execution and TCP-based data exfiltration — and in most variants also BONDUPDATER, a downloader that uses a domain generation algorithm (DGA) for DNS-based C2. The DGA for poison-frog[.]club variants generates subdomains from a unique victim ID (derived from MAC address or whoami), randomly inserted parameters, random hex characters, and hardcoded string elements — producing distinct send and receive subdomain formats. A second cluster, identified from a ClearSky tip, uses window5[.]win as the C2 domain with a URI of /update.aspx. Infrastructure pivoting confirmed that poison-frog[.]club, proxycheker[.]pro, and associated IPs (82.102.14.219, 94.23.172.164, 185.15.247.147) overlap with domains mentioned in the original FireEye report (dns-update[.]club, hpserver[.]online, anyportals[.]com), corroborating the APT34 attribution. Booz Allen also provides a YARA rule for static detection of the dropper binaries based on PDB path strings.
Extracted IOCs
- poison-frog[.]club
- proxychecker[.]pro
- proxycheker[.]pro
- window5[.]win
- 0681f2459edf28dcd99493ae8a6398d5
- 06d537af8c43f65fc467781b01047e5c
- 1de8f76404eb799c780da5830915a17e
- 277ff86501b98a4ff8c945ac4d4a7c53
- 27acdfab0a264b4ebd4dd16dae6c4e0e
- 33e86ab6621f3db7cd7e37caf42c95e5
- 347929555e8d7174d82356f47a054106
- 4ea656d10be1d6eac05d69252d270592
- 517d1d51414019272849e7c67e622597
- 52973212e6373585f55b4dd207d890ff
- 614ddccdcaf73172c1216d812595394c
- 63d6b1933f7330358a8fbfaf77532133
- 6f2ca6d892cca631c191233cb89d9b93
- 87fb0c1e0de46177390de3ee18608b21
- a602a7b6deadc3dfb6473a94d7edc9e4
- bed81e58ef8ff0b073e371d433a08855
- c3572009ca311f44a99c4fab3f3dff92
- c9f16f0be8c77f0170b9b6ce876ed7fb
- cbe2f69d9ef39093d8645d3c93fd7f21
- d9bbb27b0c5249d681179d234bff60de
- ee93a172937d37d3152d694331e59a21
- f0b278427c8841c5d1a79ed2631b1522
- 185[.]15.247.147
- 185[.]181.8.246
- 82[.]102.14.219
- 94[.]23.172.164
Tip: 30 related IOCs (4 IP, 4 domain, 0 URL, 0 email, 22 file hash) to this threat have been found.
Overlaps
Source: Kaspersky - December 2019
Detection (four cases): 4ea656d10be1d6eac05d69252d270592, 87fb0c1e0de46177390de3ee18608b21, c9f16f0be8c77f0170b9b6ce876ed7fb, poison-frog[.]club
Source: Palo Alto Network - April 2019
Detection (one case): poison-frog[.]club
Source: Mandiant - December 2017
Detection (six cases): 185[.]15.247.147, 82[.]102.14.219, 94[.]23.172.164, c9f16f0be8c77f0170b9b6ce876ed7fb, proxychecker[.]pro, proxycheker[.]pro
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions: APT34's BONDUPDATER and POWRUNER Malware Variants
Booz Allen's DarkLabs Threat Hunt team discovered seven previously unreported samples of APT34's BONDUPDATER and POWRUNER malware by pivoting from indicators published in FireEye's December 2017 report and a ClearSky tip from January 2018. The analysis revealed multiple variants of these two tools, confirmed additional attacker-controlled infrastructure, documented the malware's domain generation algorithm for the first time, and produced detection signatures including a YARA rule for the dropper binaries.
The malware is attributed to APT34 (also known as OilRig), an Iranian state-aligned cyberespionage group active since at least 2014. The attribution rests on shared C2 infrastructure with previously documented APT34 operations, identical debug strings across all variant binaries, and the same POWRUNER and BONDUPDATER codebases first reported by FireEye. Both Booz Allen and FireEye independently link these tools to Iranian-linked espionage activity targeting Middle Eastern organizations.
The goal is espionage. POWRUNER gives operators persistent remote access to compromised machines — they can run arbitrary commands and exfiltrate data over TCP. BONDUPDATER acts as a downloader that uses DNS-based communication to pull down additional payloads or instructions, making the C2 channel harder to detect and block. Together the two tools provide APT34 with a durable, covert foothold in targeted networks.
Booz Allen's report does not identify specific victim organizations. The broader FireEye and ClearSky reporting it builds on places the campaign in the Middle East, consistent with APT34's established targeting pattern. The campaign spanned at least August 2017 through early 2018, with infrastructure active across that period. The use of victim-specific fingerprinting in the DGA (MAC address, whoami) indicates targeted deployments rather than broad opportunistic infection.
Booz Allen's report does not specify targeted sectors. The source focuses on the malware variants and infrastructure rather than victim profiling. APT34's broader targeting history includes government, financial, energy, and telecommunications organizations across the Middle East — consistent with Iranian state intelligence-gathering priorities.
A dropper executable is delivered to the target and run — in the ClearSky-linked cluster, delivery was via a malicious .chm (Compiled HTML Help) file. The dropper creates a PowerShell file (rUpdateChecker.ps1) in a staging directory named to look like a Java update folder, then deletes itself. That PowerShell script creates a VBScript and a Windows Scheduled Task that runs the script every minute. The VBScript deploys POWRUNER, which connects to the attacker's C2 server over TCP to receive commands and send back data. Most variants also include BONDUPDATER, which uses a domain generation algorithm to construct unique DNS subdomains for each C2 communication — making each request appear different and resisting static blocking.
Middle Eastern organizations represent high-value intelligence targets for Iranian state-linked actors. APT34 has consistently focused on government institutions, energy companies, and critical infrastructure across the Gulf region — sectors where persistent covert access provides strategic value for Iranian foreign policy and economic interests. The use of victim-specific identifiers embedded in BONDUPDATER's DGA suggests pre-operational reconnaissance to ensure each deployment is tailored to a specific target.
Deploy the YARA rule Booz Allen published for the dropper binaries — it matches PDB path strings consistent across all seven discovered variants. Block and monitor the known C2 domains: proxycheker[.]pro, poison-frog[.]club, window5[.]win, and the four IPs in the IOC bundle. Monitor for update-masquerading file names (rUpdateChecker.ps1, GoogleUpdateschecker.vbs, JavaUpdates scheduled tasks) created in C:\ProgramData and C:\Users\Public paths. Alert on minute-frequency Scheduled Tasks executing VBScripts from non-standard locations. Enable PowerShell script block logging and inspect DNS traffic for unusually long subdomains — BONDUPDATER's DGA produces subdomain strings that are structurally distinct from legitimate DNS queries.