Remove BondUpdater Trojan — Restore Your Computer From Infections

Remove BondUpdater Trojan — Restore Your Computer From Infections

The BondUpdater Trojan is a dangerous weapon used against high-profile targets utilizing an unique infection mechanism. It is believed that the criminals behind it are highly experienced and are connected to a state-sponsored actor. Our article gives an overview of its behavior according to the collected samples and available reports, also it may be helpful in attempting to remove the virus.

Threat Summary

NameBondUpdater Trojan
Short DescriptionThe BondUpdater Trojan is a computer virus that is designed to silently infiltrate computer systems.
SymptomsThe victims may not experience any apparent symptoms of infection.
Distribution MethodFreeware Installations, Bundled Packages, Scripts and others.
Detection Tool See If Your System Has Been Affected by BondUpdater Trojan


Malware Removal Tool

User ExperienceJoin Our Forum to Discuss BondUpdater Trojan.

BondUpdater Trojan – Distribution Methods

A new Trojan called BondUpdater has been identified to be spread by a hacking collective called OilRig. This group is believed to have ties to Iran is also known under various other names: Cobalt Gypsy, Crambus, Helix Kitten or PT34 became famous with its large-scale attacks against high-profile targets. It is reported that the hackers may be a state-sponsored group that is allied with the Iranian intelligence agency.

The BondUpdater Trojan is primarily distributed using SPAM email messages that appear as being sent by a legitimate sender. The hackers will spoof the credentials, layout and design elements in order to coerce the users into interacting with the dangerous contents. The targets are reported to be a “high-ranking office” located in a country in the Middle East. We have information about a campaign that makes use of macro-infected documents. The criminal collective embeds the malicious code into documents of all popular types: presentations, rich text documents, databases and spreadsheets. Once they are opened a prompt will appear asking the users to enable the built-in macros. If this is done the infection follow.

The analysis shows that the scripts will download and execute a PowerShell based payload dropper.

The fact that the hackers rely on a social engineering technique gives them the ability to use other related techniques in future or supplementary campaigns. Examples include the following:

  • Fake Download Sites — The email messages can redirect to a counterfeit download that may appear as a legitimate vendor site or a famous Internet portals.
  • Script Redirects — Various web elements can redirect the users to the download pages from where the BondUpdater Trojan can be acquired. Examples include banners, pop-ups, in-line links and ads.

BondUpdater Trojan – Detailed Description

As soon as the PowerShell dropper is started it will download the other modules necessary to execute the infection. It has been found to run for no more than 10 minutes, afterwards it will pause before running once again if required.

The captured samples have been found to download the main Trojan executable which will set up a secure connection to the hacker-controlled server. The network analysis shows this malware instance uses a very flexible approach to controlling the infected hosts. Among its features are the following characteristics:

  • Two DNS Tunneling Variations — The BondUpdater Trojan has been found to contain two variations of code that uses the DNS tunneling protocol. The first one relies on DNS A records while the second one uses DNS TXT records.
  • Custom Action Types — Depending on the specific victims conditions several different behavior patterns will be started.
  • Additional Commands Arsenal — The security analysts state that this Trojan is particularly useful when infecting high-profile targets.

The analysis reveals that there is an interesting mechanism that is unique to this Trojan family — the command interpreter will check the file name of the TXT instruction files — a “1” value will instruct the engine to download file while “0” will run it. The fact that the communications can happen via the text files shows that it is unlikely that a signature-based analysis or automated security defenses can detect infections.

We presume that once the criminal controllers take over control of the infected systems they will initiate a series of hacker tactics. Usually one of the first modules that are launched is the data extraction one. It will automatically search the system for any strings that can expose the victim’s identity — their names, address, location, interests, phone number and any stored account credentials. The collected information can then be used for crimes such as financial abuse and identity theft. Other information that can harvested during this process includes one that may be used for campaign metrics — a report on the installed hardware components, user settings and operating system conditions.

It is very possible that the BondUpdater Trojan will also install itself as a persistent threat. This means that it will be set to automatically start once the computers are powered on. A related modification is the fact that such infections usually disable user-installed applications and system services. Another side effect is the inability to boot into the recovery boot menu.

Windows Registry modifications are also expected. The Trojan engine can create values for itself or modify already existing ones. If string belonging to the operating system are modified then the overall performance may drop. Changes to individual applications can disable certain functions.

Remove BondUpdater Trojan Trojan

If your computer system got infected with the BondUpdater Trojan Trojan, you should have a bit of experience in removing malware. You should get rid of this Trojan as quickly as possible before it can have the chance to spread further and infect other computers. You should remove the Trojan and follow the step-by-step instructions guide provided below.

Note! Your computer system may be affected by BondUpdater Trojan and other threats.
Scan Your PC with SpyHunter
SpyHunter is a powerful malware removal tool designed to help users with in-depth system security analysis, detection and removal of BondUpdater Trojan.
Keep in mind, that SpyHunter’s scanner is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter’s malware removal tool to remove the malware threats. Read our SpyHunter 5 review. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

To remove BondUpdater Trojan follow these steps:

1. Boot Your PC In Safe Mode to isolate and remove BondUpdater Trojan files and objects

Boot Your PC Into Safe Mode

1. For Windows XP, Vista and 7. 2. For Windows 8, 8.1 and 10. Fix registry entries created by malware and PUPs on your PC.

For Windows XP, Vista and 7 systems:

1. Remove all CDs and DVDs, and then Restart your PC from the “Start” menu.
2. Select one of the two options provided below:

For PCs with a single operating system: Press “F8” repeatedly after the first boot screen shows up during the restart of your computer. In case the Windows logo appears on the screen, you have to repeat the same task again.


For PCs with multiple operating systems: Тhe arrow keys will help you select the operating system you prefer to start in Safe Mode. Press “F8” just as described for a single operating system.


3. As the “Advanced Boot Options” screen appears, select the Safe Mode option you want using the arrow keys. As you make your selection, press “Enter“.

4. Log on to your computer using your administrator account


While your computer is in Safe Mode, the words “Safe Mode” will appear in all four corners of your screen.

Step 1: Open up the Start Menu.

Step 2: Click on the Power button (for Windows 8 it is the little arrow next to the “Shut Down” button) and whilst holding down “Shift” click on Restart.

Windows 8 Safe Mode Step 2 Shift Restart 2018

Step 3: After reboot, a blue menu with options will appear. From them you should choose Troubleshoot.

Windows 8 10 Safe Mode Boot Options Step 3 Choose an option 2018

Step 4: You will see the Troubleshoot menu. From this menu choose Advanced Options.

Windows 8 10 Safe Mode Boot Options Step 4 Troubleshoot 2018

Step 5: After the Advanced Options menu appears, click on Startup Settings.

Windows 8 10 Safe Mode Boot Options Step 5 Advanced 2018

Step 6: From the Startup Settings menu, click on Restart.

Windows 8 10 Safe Mode Boot Options Step 6 Startup Settings Restart 2018

Step 7: A menu will appear upon reboot. You can choose any of the three Safe Mode options by pressing its corresponding number and the machine will restart.

Windows 8 10 Safe Mode Boot Options Step 7 Safe Modes 2018

Some malicious scripts may modify the registry entries on your computer to change different settings. This is why cleaning your Windows Registry Database is recommended. Since the tutorial on how to do this is a bit long and tampering with registries could damage your computer if not done properly you should refer and follow our instructive article about fixing registry entries, especially if you are unexperienced in that area.

2. Find files created by BondUpdater Trojan on your PC

Find files created by BondUpdater Trojan

1. For Windows 8, 8.1 and 10. 2. For Windows XP, Vista, and 7.

For Newer Windows Operating Systems

Step 1:

On your keyboard press + R and write explorer.exe in the Run text box and then click on the Ok button.


Step 2:

Click on your PC from the quick access bar. This is usually an icon with a monitor and its name is either “My Computer”, “My PC” or “This PC” or whatever you have named it.


Step 3:

Navigate to the search box in the top-right of your PC’s screen and type “fileextension:” and after which type the file extension. If you are looking for malicious executables, an example may be “fileextension:exe”. After doing that, leave a space and type the file name you believe the malware has created. Here is how it may appear if your file has been found:

N.B. We recommend to wait for the green loading bar in the navination box to fill up in case the PC is looking for the file and hasn’t found it yet.

For Older Windows Operating Systems

In older Windows OS’s the conventional approach should be the effective one:

Step 1:

Click on the Start Menu icon (usually on your bottom-left) and then choose the Search preference.


Step 2:

After the search window appears, choose More Advanced Options from the search assistant box. Another way is by clicking on All Files and Folders.

search companion

Step 3:

After that type the name of the file you are looking for and click on the Search button. This might take some time after which results will appear. If you have found the malicious file, you may copy or open its location by right-clicking on it.

Now you should be able to discover any file on Windows as long as it is on your hard drive and is not concealed via special software.

Use SpyHunter to scan for malware and unwanted programs

3. Scan for malware and unwanted programs with SpyHunter Anti-Malware Tool

Scan your PC and Remove BondUpdater Trojan with SpyHunter Anti-Malware Tool and back up your data

1. Install SpyHunter to scan for BondUpdater Trojan and remove them.2. Scan with SpyHunter, Detect and Remove BondUpdater Trojan. Back up your data to secure it from malware in the future.
Step 1: Click on the “Download” button to proceed to SpyHunter’s download page.

It is recommended to run a scan before purchasing the full version of the software to make sure that the current version of the malware can be detected by SpyHunter. Click on the corresponding links to check SpyHunter’s EULA, Privacy Policy and Threat Assessment Criteria.

Step 2: Guide yourself by the download instructions provided for each browser.

Step 3: After you have installed SpyHunter, wait for it to update automatically.


Step 1: After the update process has finished, click on the ‘Malware/PC Scan’ tab. A new window will appear. Click on ‘Start Scan’.


Step 2: After SpyHunter has finished scanning your PC for any files of the associated threat and found them, you can try to get them removed automatically and permanently by clicking on the ‘Next’ button.


Step 3: If any threats have been removed, it is highly recommended to restart your PC.

Back up your data to secure it against attacks in the future

IMPORTANT! Before reading the Windows backup instructions, we highly recommend to back up your data with a cloud backup solution and insure your files against any type of loss, even from the most severe threats. We recommend you to read more about it and to download SOS Online Backup .


Martin Beltov

Martin graduated with a degree in Publishing from Sofia University. As a cyber security enthusiast he enjoys writing about the latest threats and mechanisms of intrusion.

More Posts - Website

Follow Me:
TwitterGoogle Plus

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share