Reaver
MITRE ATT&CK: S0172 View on attack.mitre.org
Aliases: Reaver
- First seen
- 2016-11-01 00:00:00
- Malware type
- trojan
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-09-01 20:45:04
- Profile updated
- 2026-07-07 15:45:00
Targeted industries: government-and-public-sector
Targeted regions: country_code:cn
Context
Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Reaver (S0172). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 73f5a52567e6afd449576d3ef683a01c8c8aa188278f4e4247008bbb6ab545d3 | 2026-09-01 | 2 |
Detection coverage
- 1 YARA rules
- 199 Sigma rules
Malware & tools used
- Shortcut Modification (attack-pattern)
- File Deletion (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- Web Protocols (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Control Panel (attack-pattern)
- Local Storage Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Windows Service (attack-pattern)
- System Information Discovery (attack-pattern)
- Query Registry (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
Detection rules
- MALPEDIA_Win_Reaver_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Reaver (report)
- threatvector.cylance.com — Reaver Mapping Connections Between Disparate Chinese Apt Groups (report)
- researchcenter.paloaltonetworks.com — Unit42 New Malware With Ties To Sunorcal Discovered (report)
- MITRE ATT&CK — S0172 (report)