BITSAdmin

BITSAdmin is a command line tool used to create and manage BITS Jobs. [1]

ID: S0190
Type: TOOL
Platforms: Windows
Contributors: Edward Millington
Version: 1.4
Created: 18 April 2018
Last Modified: 03 August 2023

Techniques Used

Domain ID Name Use
Enterprise T1197 BITS任务

BITSAdmin can be used to create BITS Jobs to launch a malicious process.[2]

Enterprise T1048 .003 替代协议渗出: Exfiltration Over Unencrypted Non-C2 Protocol

BITSAdmin can be used to create BITS Jobs to upload files from a compromised host.[1]

Enterprise T1570 横向工具传输

BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers.[3]

Enterprise T1105 输入工具传输

BITSAdmin can be used to create BITS Jobs to upload and/or download files.[1]

Groups That Use This Software

ID Name References
G0102 Wizard Spider

[4]

G0096 APT41

[5]

G1034 Daggerfly

Daggerfly has used BITSAdmin to retrieve files from remote locations to run on victim systems.[6]

G1001 HEXANE

[7]

G0065 Leviathan

[8]

G0081 Tropic Trooper

[2]

G0137 Ferocious Kitten

[9]

References