MINIBUS
- First seen
- 2023-01-15 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 13:13:02
Targeted industries: government-and-public-sector defense-and-aerospace
Context
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
Detection coverage
- 3 YARA rules
Detection rules
- SEKOIA_Backdoor_Win_Minibus (yara-rule)
- SEKOIA_Installer_Win_Minibus (yara-rule)
- MALPEDIA_Win_Minibus_Auto (yara-rule)
Reports & references
- Mandiant — Suspected Iranian Unc1549 Targets Israel Middle East (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Minibus (report)