Downdelph

MITRE ATT&CK: S0134 View on attack.mitre.org

Aliases: Delphacy, DELPHACY, Downdelph

First seen
2013-01-01 00:00:00
Malware type
downloader
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:45:02

Targeted industries: government-and-public-sector

Targeted regions: country_code:ru country_code:ua

Context

Downdelph is a first-stage downloader written in Delphi that has been used by APT28 in rare instances between 2013 and 2015.

Detection coverage

  • 2 YARA rules
  • 206 Sigma rules

Malware & tools used

  • Junk Data (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • DLL (attack-pattern)

Used by threat actors

Detection rules

  • ARKBIRD_SOLG_APT_APT28_Downdelph_Feb_2021_1 (yara-rule)
  • MALPEDIA_Win_Downdelph_Auto (yara-rule)

Reports & references

  • ESET — Eset Sednit Part3 (report)
  • contagiodump.blogspot.de — Russian Apt Apt28 Collection Of Samples (report)
  • picussecurity.com — Picus 10 Critical Mitre Attck Techniques T1055 Process Injection (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Downdelph (report)
  • labs.sentinelone.com — A Deep Dive Into Zebrocys Dropper Docs (report)
  • MITRE ATT&CK — S0134 (report)

External references