H1N1

MITRE ATT&CK: S0132 View on attack.mitre.org

Aliases: H1N1

First seen
2014-01-01 00:00:00
Malware type
loader, credential-stealer
Family
Malware family
Operating systems
windows
Related IoCs
39 (31 malicious)
Last IoC activity
2026-09-03 02:54:44
Profile updated
2026-07-07 15:29:27

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality

Context

H1N1 is a malware variant that has been distributed via a campaign using VBA macros to infect victims. Although it initially had only loader capabilities, it has evolved to include information-stealing functionality.

Recent IoC activity

31 malicious indicators in Maltiverse are attributed to H1N1 (S0132). The 20 most recently updated:

Detection coverage

  • 1 YARA rules
  • 444 Sigma rules

Malware & tools used

  • Credentials from Web Browsers (attack-pattern)
  • Taint Shared Content (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Replication Through Removable Media (attack-pattern)
  • Windows Host Firewall (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Software Packing (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Data Encoding (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Disable or Modify Tools (attack-pattern)

Detection rules

  • MALPEDIA_Win_H1N1_Auto (yara-rule)

Reports & references

  • blogs.cisco.com — H1N1 Technical Analysis Reveals New Capabilities (report)
  • MITRE ATT&CK — S0132 (report)

External references