Sakula

MITRE ATT&CK: S0074 View on attack.mitre.org

Aliases: Sakurel, VIPER, Sakula

First seen
2012-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
1551 (1549 malicious)
Last IoC activity
2026-09-02 03:10:07
Profile updated
2026-07-07 15:46:35

Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services

Targeted regions: country_code:us

Context

Sakula is a remote access tool (RAT) that first surfaced in 2012 and was used in intrusions throughout 2015.

Recent IoC activity

1,557 malicious indicators in Maltiverse are attributed to Sakula (S0074). The 20 most recently updated:

TypeIndicatorUpdatedSources
file sample da1e6d75fe0c964385eb3c12831499b106ecb674d4abb37f730c014ab23bf095.bin 2026-09-03 2
file sample 2026-09-02_a74ca93e8ed499b13aee70a30798fceb_amadey_elex_redline-stealer_rhada... 2026-09-02 1
file sample 2026-09-02_c66a04b50681fd2522bdb3e5dcb8f3b9_amadey_elex_redline-stealer_rhada... 2026-09-02 1
file sample 0ff5f622cf9a257859bc829f16cb9aa7155ed4340ac4e1ea1c4be407b83e960a 2026-09-02 1
file sample 2026-09-02_e0b6b0b2fe1bb5d17c4f965df49ccbfb_amadey_elex_redline-stealer_rhada... 2026-09-02 1
file sample 2026-09-01_95770259516531e2234414eb880e2caa_amadey_elex_karagany_redline-stea... 2026-09-02 1
file sample 2026-09-01_a5729d849d0ba1f0634ec758eebc3126_amadey_elex_redline-stealer_rhada... 2026-09-02 1
file sample 2026-09-01_ac36e84bf5e3b5cd1cfb460aa6ba2e6c_amadey_elex_redline-stealer_rhada... 2026-09-02 1
file sample fbc91b6023868c46afc6c5ebc499f7a77f11eead4df7395c13e574b801f4bb62.exe 2026-09-02 2
file sample 2026-09-01_db394973722c1433c4c85a67a33b4af6_amadey_elex_redline-stealer_rhada... 2026-09-02 1
hostname me.didichuxing.cc 2026-09-02 1
file sample 2026-09-01_f9c10b01a398ba95a6add28731098ae3_amadey_elex_karagany_redline-stea... 2026-09-02 1
file sample 1af57b30c55808916679ac4764b54834e202f78ff8da9dabcd33addbf0e77440 2026-09-01 1
file sample 2026-09-01_5dcb9227f89f69d09ba607c2032c1250_amadey_elex_redline-stealer_rhada... 2026-09-01 1
file sample 2026-09-01_61ac9b8d07e9709a83794b284ba79de7_amadey_elex_redline-stealer_rhada... 2026-09-01 1
file sample 2026-09-01_636b5470c9b53952e34191cd502457c5_amadey_elex_redline-stealer_rhada... 2026-09-01 1
file sample 2026-09-01_63e2dd88e086c3c034b381fa2ee80955_amadey_elex_redline-stealer_rhada... 2026-09-01 1
file sample 2026-09-01_764e0151e1bc15571435a9e9a7a71662_amadey_elex_redline-stealer_rhada... 2026-09-01 1
file sample 2026-09-01_790c78684f7f59c3e4ba830cc37ba5b0_amadey_elex_redline-stealer_rhada... 2026-09-01 1
file sample 2026-09-01_b5808c15ec536f6fb482ed8011d43897_amadey_elex_redline-stealer_rhada... 2026-09-01 1

Detection coverage

  • 7 YARA rules
  • 373 Sigma rules

Malware & tools used

  • Encrypted/Encoded File (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Web Protocols (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • DLL (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Rundll32 (attack-pattern)
  • Windows Service (attack-pattern)
  • File Deletion (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_MAL_Cisco_Rayinitiator_Stage_3_LINE_VIPER_Shellcode (yara-rule)
  • SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_Shellcode_Deobfuscation_Routine (yara-rule)
  • SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_Shellcode_Initial_Execution (yara-rule)
  • SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_RSA_Enc_Random_AES_Key_Gen (yara-rule)
  • SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_AES_Enc_Tasking_Exfil (yara-rule)
  • SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_ICMP_Tasking_Shellcode_Payloads (yara-rule)
  • MALPEDIA_Win_Sakula_Rat_Auto (yara-rule)

Related threat objects

Reports & references

  • secureworks.com — Sakula Malware Family (report)
  • secureworks.com — Sakula Malware Family (report)
  • MITRE ATT&CK — S0074 (report)

External references