CHEESETRAY

Aliases: CROWDEDFLOUNDER

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:45:25

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Context

CHEESETRAY is a sophisticated proxy-aware backdoor that can operate in both active and passive mode depending on the passed command-line parameters. The backdoor is capable of enumerating files and processes, enumerating drivers, enumerating remote desktop sessions, uploading and downloading files, creating and terminating processes, deleting files, creating a reverse shell, acting as a proxy server, and hijacking processes among its other functionality. The backdoor communicates with its C&C server using a custom binary protocol over TCP with port specified as a command-line parameter.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Cheesetray_Auto (yara-rule)

Reports & references

  • labs.sentinelone.com — Dprk Hidden Cobra Update North Korean Malicious Cyber Activity (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Cheesetray (report)
  • Mandiant — Rpt Apt38 2018 (report)
  • us-cert.gov — Ar20 045C (report)

External references