BITSAdmin
BITSAdmin is a legitimate Windows administrative utility that adversaries use as a dual-use tool for file transfer. The provided content associates BITSAdmin with creating BITS jobs for ingress tool transfer, lateral tool transfer, and exfiltration over unencrypted non-C2 protocols, including uploading files from a compromised host. It has been used by Daggerfly to retrieve files from remote locations for execution on victim systems. The content specifically links BITSAdmin activity to BITS jobs and transfer operations rather than bespoke malware functionality. Associated threat activity in the content includes Daggerfly intrusions. No specific industries, victim sectors, or concrete indicators of compromise are provided in the source material.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Daggerfly has used BITSAdmin to retrieve files from remote locations to run on victim systems.
Techniques & procedures
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
1 technique
Execution
Persistence
1 technique
Persistence
Stealth
1 technique
Stealth
Command and Control
1 technique
Command and Control
Exfiltration
3 techniques
Exfiltration
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows utility that can be abused to upload files from a compromised host via BITS jobs.
Windows BITS administration utility abused to download/upload files and move tools laterally using BITS jobs.
A Windows command-line utility abused to download/transfer files (living-off-the-land), enabling remote payload retrieval and execution on victim systems.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.