Description
BoomBox is a downloader responsible for executing next stage components that cyberattackers associated with APT29 have used since at least 2021. Detections under this name indicate sophisticated activity and warrant escalation beyond routine malware handling.
Stats
- First seen
- March 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
16 techniques across 6 tactics.
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.BoomBox |
| Win32.Trojan.BoomBox |