Sakula
MITRE ATT&CK: S0074 View on attack.mitre.org
Aliases: Sakurel, VIPER, Sakula
- First seen
- 2012-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1551 (1549 malicious)
- Last IoC activity
- 2026-09-02 03:10:07
- Profile updated
- 2026-07-07 15:46:35
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:us
Context
Sakula is a remote access tool (RAT) that first surfaced in 2012 and was used in intrusions throughout 2015.
Recent IoC activity
1,557 malicious indicators in Maltiverse are attributed to Sakula (S0074). The 20 most recently updated:
Detection coverage
- 7 YARA rules
- 373 Sigma rules
Malware & tools used
- Encrypted/Encoded File (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Web Protocols (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- DLL (attack-pattern)
- Windows Command Shell (attack-pattern)
- Rundll32 (attack-pattern)
- Windows Service (attack-pattern)
- File Deletion (attack-pattern)
Used by threat actors
- Deep Panda (threat-actor)
Detection rules
- SIGNATURE_BASE_MAL_Cisco_Rayinitiator_Stage_3_LINE_VIPER_Shellcode (yara-rule)
- SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_Shellcode_Deobfuscation_Routine (yara-rule)
- SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_Shellcode_Initial_Execution (yara-rule)
- SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_RSA_Enc_Random_AES_Key_Gen (yara-rule)
- SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_AES_Enc_Tasking_Exfil (yara-rule)
- SIGNATURE_BASE_MAL_Cisco_LINE_VIPER_ICMP_Tasking_Shellcode_Payloads (yara-rule)
- MALPEDIA_Win_Sakula_Rat_Auto (yara-rule)
Related threat objects
- Sakula RAT (malware)
Reports & references
- secureworks.com — Sakula Malware Family (report)
- secureworks.com — Sakula Malware Family (report)
- MITRE ATT&CK — S0074 (report)