CREAMSICLE

First seen
2023-02-17 00:00:00
Malware type
trojan, ransomware
Family
Malware family
Profile updated
2026-07-07 12:36:41

Targeted industries: financial-services government-and-public-sector

Context

CREAMSICLE is a malware family associated with financial and government-targeted attacks. It primarily functions as a trojan with ransomware capabilities, leveraging sophisticated methods for data encryption and exfiltration.

Reports & references

  • Mandiant — Rpt Apt30 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Creamsicle (report)

External references