CHERRYSPY
- Malware type
- backdoor
- Profile updated
- 2026-07-07 13:14:03
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ua
Context
According to CERT-UA, this is a PyArmor-protected backdoor capable of execution dynamically downloaded Python code.
Reports & references
- CERT-UA — 4697016 (report)
- malpedia.caad.fkie.fraunhofer.de — Py.Cherryspy (report)
- recordedfuture.com — Russia Aligned Tag 110 Targets Tajikistan With Macro Enabled (report)
- go.recordedfuture.com — Cta 2025 0522 (report)