MINIBUS

First seen
2023-01-15 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:13:02

Targeted industries: government-and-public-sector defense-and-aerospace

Context

According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.

Detection coverage

  • 3 YARA rules

Detection rules

  • SEKOIA_Backdoor_Win_Minibus (yara-rule)
  • SEKOIA_Installer_Win_Minibus (yara-rule)
  • MALPEDIA_Win_Minibus_Auto (yara-rule)

Reports & references

  • Mandiant — Suspected Iranian Unc1549 Targets Israel Middle East (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Minibus (report)

External references