Bitsadmin - Tool

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
January 10, 2026
Last Seen
July 20, 2026

Bitsadmin is a tool tracked across 5 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed January 10, 2026; most recent activity July 20, 2026.

Overview

Bitsadmin is a Windows command-line utility for the Background Intelligent Transfer Service (BITS) used for background file transfers. While legitimate, it is frequently abused by threat actors to download payloads or stage components, making it a notable indicator in malware dropper and downloader activity. The current observed activity around Astaroth's reemergence as Boto-Cor-de-Rosa underscores evolving delivery vectors and the need to monitor downloader-like behaviors in Windows environments.

Related Threat Clusters

Recent Intelligence Reports

  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • Inside an Exposed Malware Delivery Lab: OPSEC Failures Behind a WebDAV Phishing Operation — Rapid7 · July 20, 2026
  • UAC — Cybersecuritynews · May 19, 2026
  • UAC — Gbhackers · May 19, 2026
  • Jewelbug Apt Russia — www.security.com · May 5, 2026
  • CloudZ RAT potentially steals OTP messages using Pheno plugin — Blog.Talosintelligence · May 5, 2026
  • Astaroth Trojan Reemerges as Boto-Cor-de-Rosa, Spreads via WhatsApp in Brazil — Webpronews · January 10, 2026

CVSS v3.1 Breakdown