Netskope Threat Labs

BITSAdmin

ATP Sandbox Adv. HeuristicsAV

BITSAdmin is a command line tool for creating and managing Windows background transfer jobs, which cyberattackers abuse to download payloads and exfiltrate data over the legitimate BITS service. Because the transfers come from a signed system binary, malicious use blends into routine network activity.

First seen
February 2022
Last seen
September 2026

4 techniques across 4 tactics.

TA0005 Stealth

TA0008 Lateral Movement

  • T1570Lateral Tool Transfer

TA0011 Command and Control

  • T1105Ingress Tool Transfer

TA0010 Exfiltration

  • T1048Exfiltration Over Alternative Protocol
    • T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
Alert Name
Document-HTML.Exploit.BitsAdmin
Exploit.HTML.BitsAdmin.Gen
Script.Exploit.BitsAdmin