Reaver

MITRE ATT&CK: S0172 View on attack.mitre.org

Aliases: Reaver

First seen
2016-11-01 00:00:00
Malware type
trojan
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-09-01 20:45:04
Profile updated
2026-07-07 15:45:00

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn

Context

Reaver is a malware family that has been in the wild since at least late 2016. Reporting indicates victims have primarily been associated with the "Five Poisons," which are movements the Chinese government considers dangerous. The type of malware is rare due to its final payload being in the form of Control Panel items.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Reaver (S0172). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 73f5a52567e6afd449576d3ef683a01c8c8aa188278f4e4247008bbb6ab545d3 2026-09-01 2

Detection coverage

  • 1 YARA rules
  • 199 Sigma rules

Malware & tools used

  • Shortcut Modification (attack-pattern)
  • File Deletion (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Web Protocols (attack-pattern)
  • Archive via Custom Method (attack-pattern)
  • Control Panel (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)

Detection rules

  • MALPEDIA_Win_Reaver_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Reaver (report)
  • threatvector.cylance.com — Reaver Mapping Connections Between Disparate Chinese Apt Groups (report)
  • researchcenter.paloaltonetworks.com — Unit42 New Malware With Ties To Sunorcal Discovered (report)
  • MITRE ATT&CK — S0172 (report)

External references