BrittleBush is a trojan associated with the Palestinian-aligned espionage threat actor TA402, also tracked as Molerats, Arid Viper, and ALUMINUM SARATOGA. It has been observed in targeted campaigns against Middle Eastern governments, foreign policy think tanks, and a state-affiliated airline, particularly in operations from late 2021 through early 2022. In those campaigns, BrittleBush was delivered alongside the NimbleMamba implant as part of highly selective intelligence-collection activity focused on victims in the Middle East and North Africa.
BrittleBush establishes communications with a remote server, retrieves Base64-encoded commands, and executes those commands on infected systems. Reported commanding has used Base64-encoded JSON structures. Its observed role is consistent with a lightweight remote-command trojan used for post-compromise tasking on victim machines. Public reporting directly supports command retrieval and execution behavior, but does not provide enough high-confidence detail to classify broader functionality beyond that.
Observed delivery chains relied on spearphishing lures and regionally restricted infrastructure. Victims received links that, when accessed from targeted geographies, led to malicious archives containing NimbleMamba and often BrittleBush; later variants used Dropbox-hosted payload delivery and attacker-controlled WordPress redirect sites. The malware has been linked to TA402’s continuing evolution of targeted espionage tooling and delivery tradecraft in campaigns centered on Middle Eastern intelligence requirements.
BrittleBush is associated with Windows-targeted intrusion activity because it was delivered as an executable within archive-based phishing chains used by TA402 against desktop endpoints. Its known use is tied to espionage operations rather than financially motivated crime or disruptive attacks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ALUMINUM SARATOGA ... Tools ... BlackShades, BrittleBush, DarkComet, LastConn, Micropsia, NimbleMamba, PoisonIvy, QuasarRAT, XtremeRat
Also delivered is a trojan dubbed BrittleBush that establishes communications with a remote server to retrieve Base64-encoded commands to be executed on the infected machines.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a tool used by the ALUMINUM SARATOGA threat profile.
A trojan delivered alongside NimbleMamba that contacts a remote server to fetch Base64-encoded commands for execution on infected systems.
A small trojan delivered alongside NimbleMamba in later campaign variants. It communicated with easyuploadservice[.]com and received commands as a base64-encoded JSON structure.
Malware used in late-2021/early-2022 phishing campaigns leveraging actor-controlled infrastructure and Dropbox links.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.