Cinoshi
Aliases: Agniane
- First seen
- 2020-05-15 00:00:00
- Malware type
- rat, trojan
- Family
- Malware family
- Last IoC activity
- 2026-05-24 02:56:45
- Profile updated
- 2026-07-07 14:52:47
Targeted industries: financial-services government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:ru
Context
Cinoshi, also known as Agniane, is a remote access trojan (RAT) known for targeting financial services and governmental sectors. It is used in cyber-espionage campaigns and has been detected in several countries, including the US and Russia.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Infostealer_Win_Cinoshistealer (yara-rule)
- SEKOIA_Win_Malware_Agnianestealer (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Cinoshi (report)
- zscaler.com — Agniane Stealer Dark Webs Crypto Threat (report)
- twitter.com — 1633807752127475713 (report)
- youtube.com — Watch (report)
- cyble.com — Cinoshi Project And The Dark Side Of Free Maas (report)