CrimsonIAS

First seen
2017-01-01 00:00:00
Malware type
backdoor
Last IoC activity
2026-07-18 02:08:03
Profile updated
2026-07-07 14:55:19

Targeted industries: government-and-public-sector

Targeted regions: country_code:in

Context

According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017. It enables operators to run command line tools, exfiltrate files, and upload files to the infected machine. CrimsonIAS is notable as it listens for incoming connections only; making it different from typical Windows backdoors that beacons out.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Crimsonias (report)
  • threatconnect.com — Crimsonias Listening For An 3V1L User 2 (report)
  • threatconnect.com — Crimsonias Listening For An 3V1L User (report)

External references