Lurid

MITRE ATT&CK: S0010 View on attack.mitre.org

Aliases: Enfal, Lurid

First seen
2006-01-01 00:00:00
Malware type
rat, spyware
Family
Malware family
Operating systems
windows
Related IoCs
4 (3 malicious)
Last IoC activity
2026-08-30 03:30:13
Profile updated
2026-07-07 15:43:40

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ru country_code:ua country_code:us

Context

Lurid is a malware family that has been used by several groups, including PittyTiger, in targeted attacks as far back as 2006.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to Lurid (S0010). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname set.yandex-vip.com 2026-09-02 1
hostname press.mailru-pro.com 2026-07-31 2
hostname inet.google-officeonline.com 2026-03-07 1
file sample e2c6dee089bd8c3d23ab7d422e25c5f21553bda2c805f9e63765371ba71feaa9 2025-12-02 1

Detection coverage

  • 1 YARA rules
  • 2 Sigma rules

Malware & tools used

  • Symmetric Cryptography (attack-pattern)
  • Archive Collected Data (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Enfal_Auto (yara-rule)

Reports & references

  • secureworks.com — Bronze Union (report)
  • secureworks.com — Bronze Palace (report)
  • Mandiant — Spy Of The Tiger (report)
  • MITRE ATT&CK — G0011 (report)
  • research.checkpoint.com — Vicious Panda The Covid Campaign (report)
  • web.archive.org — Globalthreatintelreport (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Enfal (report)
  • researchcenter.paloaltonetworks.com — Cmstar Downloader Lurid And Enfals New Cousin (report)
  • bsk-consulting.de — How To Write Simple But Sound Yara Rules Part 2 (report)
  • Trend Micro — Wp Detecting Apt Activity With Network Traffic Analysis (report)
  • Trend Micro — Wp Dissecting Lurid Apt (report)
  • MITRE ATT&CK — S0010 (report)

External references