Ondritols

Aliases: Onedrivetools

Malware type
backdoor, downloader
Family
Malware family
Profile updated
2026-07-07 15:03:31

Targeted industries: professional-services technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:de

Context

According to Symantec, this malware has been deployed against IT services companies in the U.S. and Europe. A multi-stage backdoor, the first stage is a downloader that authenticates to Microsoft Graph API and downloads the second stage payload from OneDrive and executes it. The main payload will download a publicly available file from GitHub. It will then create a folder in OneDrive named deviceId_n_ for each infected machine and upload a file to OneDrive to signal the attackers the status of a new infection.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Ondritols_Auto (yara-rule)

Reports & references

  • security.com — Cloud Espionage Attacks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ondritols (report)

External references