LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0018: admin@338

MITRE ATT&CK G0018: admin@338 Group details, with detection guidance, relationships and mapped CVEs.

EnterpriseG0018GroupObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

admin@338 matters because the ATT&CK record links the group to targeted lure-based delivery, public RAT use such as PoisonIvy, non-public backdoors, and post-compromise discovery activity. For leaders, the decision value is whether the organization can prove it would see a targeted email leading to Windows command execution, RAT/backdoor persistence or communications, and rapid host/network/account discovery before follow-on activity expands.

Executive priority

Prioritize this as a targeted-intrusion readiness scenario rather than a single malware problem. Organizations involved in financial, economic, trade policy, media, or similarly sensitive decision-making should use it to test email security, endpoint visibility, Windows administrative command monitoring, incident response triage, and evidence needed for audit or regulatory reporting. The key business question is: can security teams connect a suspicious attachment or exploit event to host discovery, account/group enumeration, network reconnaissance, and possible backdoor activity quickly enough to contain affected systems?

Technical view

ATT&CK provides no official detection text and no platform list for the intrusion-set object itself, but relationships show use of Windows-oriented software and utilities including PoisonIvy, LOWBALL, BUBBLEWRAP, Net, Systeminfo, ipconfig, and netstat. Validation should focus on the related techniques: spearphishing attachment and malicious file execution, client-side exploitation, Windows command shell use, local account and group discovery, service discovery, system information discovery, file and directory discovery, and network configuration/connection discovery. SOC teams should test whether endpoint, email, and network telemetry can correlate these behaviors into a single intrusion storyline instead of treating each command as benign administration.

Likely telemetry

  • Email security logs for targeted messages, attachments, attachment detonation results, and user interaction indicators
  • Endpoint process creation telemetry for cmd.exe and Windows utilities such as net, systeminfo, ipconfig, and netstat
  • Command-line arguments and parent/child process relationships around document readers, archive tools, shells, and administrative utilities
  • Endpoint file, registry, and startup/persistence evidence relevant to backdoors that run at boot
  • Network connection metadata from endpoints, including unusual outbound RAT or backdoor communications where locally observable

Detection direction

  • Validate correlation logic for phishing attachment or malicious-file execution followed by command shell activity and discovery commands.
  • Tune for suspicious clustering of discovery commands rather than alerting on single utilities alone, since Net, ipconfig, systeminfo, and netstat are legitimate administrative tools.
  • Review allowlists and suppression rules for common admin commands; excessive suppression can hide post-compromise discovery.
  • Hunt for host discovery followed by backdoor-like persistence or outbound communications, using the related software context for PoisonIvy, LOWBALL, and BUBBLEWRAP without assuming every environment has those specific samples.
  • Confirm detections retain command-line, parent process, user context, hostname, and network destination details needed for incident reconstruction.

Mitigation priorities

  • Strengthen email attachment controls, sandboxing, and user-reporting workflows for targeted lure scenarios.
  • Maintain timely patching of client applications to reduce exposure to exploitation for client execution.
  • Harden endpoint execution controls and monitor suspicious child processes from document or attachment-handling applications.
  • Limit and monitor local administrative privileges so account and group discovery does not easily lead to privilege escalation or lateral movement decisions.
  • Ensure EDR, email, and network logging are retained long enough to reconstruct an intrusion from initial delivery through discovery and backdoor activity.
Additional notes and limits

This take is based on the ATT&CK v19.1 intrusion-set record for admin@338 and its supplied relationships. The group description cites use of newsworthy lures, targeting of financial/economic/trade policy organizations, public RATs such as PoisonIvy, and non-public backdoors. Relationship context adds LOWBALL, BUBBLEWRAP, Windows utilities, and discovery/execution/initial-access techniques that are useful for defensive validation.

The intrusion-set object has no official detection text, no tactics listed directly on the object, and no platform list for the group itself. Related software and techniques provide useful context, but local telemetry, control configuration, and current threat intelligence are required before assessing exposure or detection coverage. This summary does not claim current activity or confirmed targeting of any specific organization.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

admin@338

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

12 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.001Spearphishing AttachmentSub-techniqueThis object uses Spearphishing Attachment.
EnterpriseT1016System Network Configuration DiscoveryThis object uses System Network Configuration Discovery.
EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-techniqueThis object uses Match Legitimate Resource Name or Location.
EnterpriseT1083File and Directory DiscoveryThis object uses File and Directory Discovery.
EnterpriseT1069.001Local GroupsSub-techniqueThis object uses Local Groups.
EnterpriseT1049System Network Connections DiscoveryThis object uses System Network Connections Discovery.
EnterpriseT1087.001Local AccountSub-techniqueThis object uses Local Account.
EnterpriseT1203Exploitation for Client ExecutionThis object uses Exploitation for Client Execution.
EnterpriseT1007System Service DiscoveryThis object uses System Service Discovery.
EnterpriseT1204.002Malicious FileSub-techniqueThis object uses Malicious File.
EnterpriseT1082System Information DiscoveryThis object uses System Information Discovery.
EnterpriseT1059.003Windows Command ShellSub-techniqueThis object uses Windows Command Shell.
Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0043: BUBBLEWRAP

BUBBLEWRAP is a full-featured, second-stage backdoor used by the admin@338 group. It is set to run when the system boots and includes functionality to check, upload, and register plug-ins that can further enhance its capabilities. [1]

Windows
ToolEnterprise

S0039: Net

The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]

Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.

Windows
ToolEnterprise

S0104: netstat

netstat is an operating system utility that displays active TCP connections, listening ports, and network statistics. [1]

ToolEnterprise

S0100: ipconfig

ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration. [1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
895fbb5d4a442afb...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle895fbb5d4a44…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  2. [2]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  3. [3]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  4. [4]
    admin@338

    (Citation: FireEye admin@338)

  5. [5]
    admin@338

    (Citation: FireEye admin@338)

  6. [6]
    admin@338

    (Citation: FireEye admin@338)

  7. [7]
    mitre-attackG0018
    Open source URL
  8. [8]
    mitre-attackG0018
    Open source URL
  9. [9]
    mitre-attackG0018
    Open source URL
  10. [10]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  11. [11]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  12. [12]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  13. [13]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  14. [14]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  15. [15]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  16. [16]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  17. [17]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  18. [18]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  19. [19]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  20. [20]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  21. [21]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  22. [22]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  23. [23]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  24. [24]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  25. [25]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  26. [26]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  27. [27]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  28. [28]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  29. [29]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  30. [30]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  31. [31]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  32. [32]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  33. [33]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  34. [34]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  35. [35]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  36. [36]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  37. [37]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  38. [38]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  39. [39]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  40. [40]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
  41. [41]
    FireEye admin@338

    FireEye Threat Intelligence. (2015, December 1). China-based Cyber Threat Group Uses Dropbox for Malware Communications and Targets Hong Kong Media Outlets. Retrieved December 4, 2015.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.