• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Bird Agent Backdoor config.toml MachineGuid Binding

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 22 days ago•0•0•3

    Detects Bird Agent malware samples that exhibit characteristic behavior of binding configuration decryption to the Windows MachineGuid registry value. The rule identifies binaries that contain references to 'config.toml' and the Windows Cryptography registry key used to retrieve the MachineGuid, often used as a unique machine-based key for decryption.

    YARA

    Tags

    T1027 - Obfuscated Files or InformationT1552.002 - Credentials in RegistryTA0005 - StealthMalware DetectedFile Executable DetectedWindows

    Found in

    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago
    • Three Threat Groups Target Russian Enterprises with BackdoorsLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?