Bitsadmin is a tool tracked across 5 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed January 10, 2026; most recent activity July 20, 2026.
Bitsadmin is a Windows command-line utility for the Background Intelligent Transfer Service (BITS) used for background file transfers. While legitimate, it is frequently abused by threat actors to download payloads or stage components, making it a notable indicator in malware dropper and downloader activity. The current observed activity around Astaroth's reemergence as Boto-Cor-de-Rosa underscores evolving delivery vectors and the need to monitor downloader-like behaviors in Windows environments.
In 2024, ESET identified a new China-aligned APT group named LongNosedGoblin, which targets governmental entities in Southeast Asia and Japan. The group employs a custom toolset, primarily using C#/.NET applications, to…
UAC-0184 has deployed a multi-stage malware chain that utilizes the Windows bitsadmin tool and HTA files to deliver obfuscated payloads. This campaign primarily targets Ukrainian military networks, specifically accounts…
A new malware campaign involving the CloudZ remote access trojan (RAT) and its Pheno plugin is targeting Microsoft’s Phone Link feature to intercept SMS-based one-time passwords (OTPs) and other sensitive data from…
An exposed server functioning as a malware delivery lab was discovered following an MDR alert. The lab contained over 1,000 artifacts, showcasing how attackers are leveraging generative AI for rapid lure generation and…
The Astaroth banking trojan has resurfaced, now spreading through WhatsApp in Brazil under the name 'Boto-Cor-de-Rosa' or 'Pink Dolphin.' This campaign utilizes worm-like tactics to target users and steal financial…