APT / THREAT GROUP
MINIBUS
2
aliases
Last seen:Mar 17, 2026
Intelligence Profile
According to Mandiant, this is a custom backdoor that provides a more flexible code-execution interface and enhanced reconnaissance features compared to MINIBIKE.
Threat Analysis
MINIBUS is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
External References
Quick Facts
TypeAPT / Threat Group
Aliases2
Also Known As
MINIBUSwin.minibus
External Intelligence
Malpedia: win.minibusResearch Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.