CrimsonIAS
- First seen
- 2017-01-01 00:00:00
- Malware type
- backdoor
- Last IoC activity
- 2026-07-18 02:08:03
- Profile updated
- 2026-07-07 14:55:19
Targeted industries: government-and-public-sector
Targeted regions: country_code:in
Context
According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017. It enables operators to run command line tools, exfiltrate files, and upload files to the infected machine. CrimsonIAS is notable as it listens for incoming connections only; making it different from typical Windows backdoors that beacons out.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Crimsonias (report)
- threatconnect.com — Crimsonias Listening For An 3V1L User 2 (report)
- threatconnect.com — Crimsonias Listening For An 3V1L User (report)