CHERRYSPY

Malware type
backdoor
Profile updated
2026-07-07 13:14:03

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ua

Context

According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.

Reports & references

  • CERT-UA — 4697016 (report)
  • malpedia.caad.fkie.fraunhofer.de — Py.Cherryspy (report)
  • recordedfuture.com — Russia Aligned Tag 110 Targets Tajikistan With Macro Enabled (report)
  • go.recordedfuture.com — Cta 2025 0522 (report)

External references