Netskope Threat Labs

BoomBox

ATP Sandbox Adv. Heuristics

BoomBox is a downloader responsible for executing next stage components that cyberattackers associated with APT29 have used since at least 2021. Detections under this name indicate sophisticated activity and warrant escalation beyond routine malware handling.

First seen
March 2022
Last seen
October 2026

16 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

  • T1027Obfuscated Files or Information
  • T1036Masquerading
  • T1140Deobfuscate/Decode Files or Information
  • T1218System Binary Proxy Execution
  • T1480Execution Guardrails

TA0007 Discovery

TA0011 Command and Control

TA0010 Exfiltration

  • T1567Exfiltration Over Web Service
Alert Name
ByteCode-MSIL.Trojan.BoomBox
Win32.Trojan.BoomBox