[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLS9U_0uTwqXdSWTOeu4HaPZ8-XnZFAQlfe4HJ786Xyc":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":50,"createdAt":50,"_status":49},471,"How does PoisonFrog achieve persistence on the victim machine?","PoisonFrog creates two scheduled tasks named `\\UpdateTasks\\UpdateTask` and `\\UpdateTasks\\UpdateTaskHosts`, both running every 10 minutes. These tasks execute `UpdateTask.vbs`, which loads two PowerShell scripts (`dUpdater.ps1` and `hUpdater.ps1`) with current user and System permissions, as detailed in the [Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse](\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-poisonfrog-and-glimpse) article.","\u003Cp>PoisonFrog creates two scheduled tasks named `\\UpdateTasks\\UpdateTask` and `\\UpdateTasks\\UpdateTaskHosts`, both running every 10 minutes. These tasks execute `UpdateTask.vbs`, which loads two PowerShell scripts (`dUpdater.ps1` and `hUpdater.ps1`) with current user and System permissions, as detailed in the [Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse](\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-poisonfrog-and-glimpse) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-apt34-leaked-tools-poisonfrog-and-glimpse\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-poisonfrog-achieve-persistence-on-the-victim-machine-1777483527292","PoisonFrog, persistence, scheduled tasks, PowerShell, APT34",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":46,"updatedAt":47,"createdAt":48,"_status":49},118,"Analysis of APT34 Leaked Tools - PoisonFrog and Glimpse","analysis-of-apt34-leaked-tools-poisonfrog-and-glimpse","Technical analysis of APT34's leaked PoisonFrog and Glimpse tools, covering PowerShell Trojans, Node.js C2 servers, and DNS tunneling techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, six tools from APT34 were leaked. This article analyzes PoisonFrog and Glimpse solely from a technical perspective.\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalware-research.org\u002Fapt34-hacking-tools-leak\u002Famp\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Analysis of PoisonFrog\u003C\u002Fli>\u003Cli>Analysis of Glimpse\u003C\u002Fli>\u003Cli>Summary\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Analysis of PoisonFrog\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding leaked file is named posion frog\u003C\u002Fp>\u003Cp>Includes two parts of files:\u003C\u002Fp>\u003Cul>\u003Cli>agent, containing the file poisonfrog.ps1, which is a Trojan program implemented via PowerShell\u003C\u002Fli>\u003Cli>server side, corresponding to the Trojan control end, developed using Node.js\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Functions implemented by the agent\u003C\u002Fh3>\u003Ch4>1. Releases three files in the %public%\\Public folder\u003C\u002Fh4>\u003Cul>\u003Cli>dUpdater.ps1\u003C\u002Fli>\u003Cli>hUpdater.ps1\u003C\u002Fli>\u003Cli>UpdateTask.vbs\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The specific functions of the released files are as follows:\u003C\u002Fp>\u003Cp>(1) dUpdater.ps1\u003C\u002Fp>\u003Col>\u003Cli>Generates a unique identifier for the current system\u003C\u002Fli>\u003Cli>Reads the proxy settings of the current system\u003C\u002Fli>\u003Cli>Downloads files from the C2 server via HTTP protocol\u003C\u002Fli>\u003Cli>Performs further operations based on the content of the downloaded files, including executing commands, uploading files, and downloading files\u003C\u002Fli>\u003C\u002Fol>\u003Cp>(2) hUpdater.ps1\u003C\u002Fp>\u003Col>\u003Cli>Generate a unique identifier for the current computer\u003C\u002Fli>\u003Cli>Create the following folders\u003C\u002Fli>\u003C\u002Fol>\u003Cul>\u003Cli>%public%\\Public\\\u003Cid>\u003C\u002Fid>\u003C\u002Fli>\u003Cli>%public%\\Public\\\u003Cid>\\reveivebox\u003C\u002Fid>\u003C\u002Fli>\u003Cli>%public%\\Public\\\u003Cid>\\sendbox\u003C\u002Fid>\u003C\u002Fli>\u003Cli>%public%\\Public\\\u003Cid>\\done\u003C\u002Fid>\u003C\u002Fli>\u003C\u002Ful>\u003Col>\u003Cli>Receive control commands from C2 server via DNS A records\u003C\u002Fli>\u003Cli>Execute commands and return results\u003C\u002Fli>\u003C\u002Fol>\u003Cp>(3)UpdateTask.vbs\u003C\u002Fp>\u003Cp>Content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>command0 = \"Powershell.exe -exec bypass -file C:\\Users\\Public\\Public\\hUpdater.ps1\"\u003Cbr>set Shell0 = CreateObject(\"wscript.shell\")\u003Cbr>shell0.run command0, 0, false\u003Cbr>command1 = \"Powershell.exe -exec bypass -file C:\\Users\\Public\\Public\\dUpdater.ps1\"\u003Cbr>set Shell1 = CreateObject(\"wscript.shell\")\u003Cbr>shell1.run command1, 0, false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Used to load PowerShell scripts dUpdater.ps1 and hUpdater.ps1\u003C\u002Fp>\u003Ch4>2. Create two scheduled tasks\u003C\u002Fh4>\u003Cul>\u003Cli>Named \\UpdateTasks\\UpdateTask, runs every 10 minutes, executes UpdateTask.vbs with current user permissions\u003C\u002Fli>\u003Cli>Named \\UpdateTasks\\UpdateTaskHosts, runs every 10 minutes, executes UpdateTask.vbs with System permissions\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Analysis of the server side\u003C\u002Fh3>\u003Cp>Implemented via Node.js\u003C\u002Fp>\u003Cp>Requires installation of third-party packages via npm before use; specific installation commands are located in the file install_packages.bat\u003C\u002Fp>\u003Cp>index.js is the main program\u003C\u002Fp>\u003Cp>To prevent misuse, the code for the control side is not analyzed in detail, nor are specific setup methods provided\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In my previous articles 'Node.js in Penetration Testing—Implementation of a Downloader' and 'Node.js in Penetration Testing—Hiding Real Code Using C++ Addons', I introduced the use of Node.js. Basic knowledge of Node.js can be referenced from these articles\u003C\u002Fp>\u003Cp>Using Node.js to implement the server side has the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Simple and easy-to-understand syntax\u003C\u002Fli>\u003Cli>Lightweight and efficient\u003C\u002Fli>\u003Cli>Can be deployed simultaneously on Windows and Linux systems\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>3. Public clues about this tool\u003C\u002Fh3>\u003Col>\u003Cli>APT34 used CVE-2017-11882 to spread this Trojan, and FireEye analyzed the sample:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Fwww.fireeye.com\u002Fblog\u002Fthreat-research\u002F2017\u002F12\u002Ftargeted-attack-in-middle-east-by-apt34.html\u003C\u002Fp>\u003Col>\u003Cli>Palo Alto Networks named it Early BondUpdater, analysis materials of the sample:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Funit42.paloaltonetworks.com\u002Fdns-tunneling-in-the-wild-overview-of-oilrigs-dns-tunneling\u002F\u003C\u002Fp>\u003Ch2>0x03 Analysis of Glimpse\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The corresponding leaked file is named Glimpse\u003C\u002Fp>\u003Cp>Includes four parts of files:\u003C\u002Fp>\u003Cul>\u003Cli>Agent, containing four files: dns.ps1, dns_main.ps1, refineddns_main.ps1, and runner_.vbs\u003C\u002Fli>\u003Cli>Panel, containing a C# developed interface program, which is the graphical Trojan control interface\u003C\u002Fli>\u003Cli>Server, a Node.js developed Trojan control interface\u003C\u002Fli>\u003Cli>Read me.txt, configuration documentation\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. Functions implemented by the agent\u003C\u002Fh3>\u003Cp>The functions of the three files dns.ps1, dns_main.ps1, and refineddns_main.ps1 are identical\u003C\u002Fp>\u003Cp>The original version is dns_main.ps1\u003C\u002Fp>\u003Cp>dns.ps1 and refineddns_main.ps1 only replace variable names with meaningless obfuscated strings\u003C\u002Fp>\u003Cp>The functionality of dns_main.ps1 is as follows:\u003C\u002Fp>\u003Col>\u003Cli>Create the folder %public%\\Libraries\u003C\u002Fli>\u003Cli>Check if the file %public%\\Libraries\\lock exists\u003C\u002Fli>\u003C\u002Fol>\u003Cul>\u003Cli>If it does not exist, create the file and write the PID of the current PowerShell process\u003C\u002Fli>\u003Cli>If the file exists, read its creation time; if it has been more than 10 minutes since creation, exit the process and delete the lock file\u003C\u002Fli>\u003C\u002Ful>\u003Col>\u003Cli>Generate a unique identifier for the current system and write it to the file %public%\\Libraries\\quid\u003C\u002Fli>\u003Cli>Create the following folders:\u003C\u002Fli>\u003C\u002Fol>\u003Cul>\u003Cli>%public%\\Libraries\\files\u003C\u002Fli>\u003Cli>%public%\\Libraries\\\u003Cid>\u003C\u002Fid>\u003C\u002Fli>\u003Cli>%public%\\Libraries\\\u003Cid>\\reveivebox\u003C\u002Fid>\u003C\u002Fli>\u003Cli>%public%\\Libraries\\\u003Cid>\\sendbox\u003C\u002Fid>\u003C\u002Fli>\u003Cli>%public%\\Libraries\\\u003Cid>\\done\u003C\u002Fid>\u003C\u002Fli>\u003C\u002Ful>\u003Col>\u003Cli>Receive control commands from the C2 server via DNS A records or DNS TXT records\u003C\u002Fli>\u003Cli>Execute commands and return results\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>2. Analysis of the server\u003C\u002Fh3>\u003Cp>Implemented via Node.js\u003C\u002Fp>\u003Cp>Before use, third-party packages must be installed via npm; specific installation commands are located in the file Read me.txt\u003C\u002Fp>\u003Cp>Compared to PoisonFrog, Glimpse has optimized its code structure and added the functionality of transmitting data via DNS TXT records\u003C\u002Fp>\u003Cp>To prevent misuse, the code of the control side is not analyzed in detail, nor are specific setup methods provided\u003C\u002Fp>\u003Ch3>3. Public clues about this tool\u003C\u002Fh3>\u003Col>\u003Cli>Palo Alto Networks named it Updated BondUpdater; analysis materials of the sample:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Funit42.paloaltonetworks.com\u002Funit42-oilrig-uses-updated-bondupdater-target-middle-eastern-government\u002F\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For PoisonFrog and Glimpse, although the tool source code was leaked this time, their samples were captured as early as 2017 and have been thoroughly analyzed. Personally, I believe there is no risk of large-scale misuse of these tools. Additionally, using the DNS protocol to transmit data is a very old method, and I do not think this tool will lead to an upgrade in malware technology.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",4,"published","2026-02-02T07:51:00.067Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"APT34 PoisonFrog & Glimpse Analysis: Leaked Tools Technical Review","APT34, PoisonFrog, Glimpse, malware analysis, cybersecurity, PowerShell, Node.js, DNS tunneling, CVE-2017-11882",false,[],{"docs":41,"hasNextPage":38},[42,43,44,45,4],475,474,473,472,{"title":30,"description":30,"image":30},"2026-07-24T02:07:23.817Z","2026-07-23T16:01:37.968Z","draft","2026-07-23T16:12:33.766Z"]