DADSTACHE

First seen
2022-05-15 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 12:53:10

Context

DADSTACHE is a sophisticated backdoor malware with capabilities for data exfiltration. Its full extent and specific targets remain unclear due to limited available information.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Dadstache_Auto (yara-rule)

Reports & references

  • elastic.co — Advanced Techniques Used In Malaysian Focused Apt Campaign (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Dadstache (report)
  • medium.com — Dad Theres A Rat In Here E3729B65Bf7A (report)
  • twitter.com — 1204584085395517440 (report)
  • medium.com — Apt40 Goes From Template Injections To Ole Linkings For Payload Delivery 99Eb43170A97 (report)
  • twitter.com — 1199978327697694720 (report)
  • danielplohmann.github.io — Kf Sandbox Necromancy (report)

External references