DEEPDATA
- First seen
- 2021-05-01 00:00:00
- Malware type
- trojan
- Profile updated
- 2026-07-07 13:15:10
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
According to Volexity, DEEPDATA is a modular post-exploitation tool for Windows that facilitates collection of sensitive information from a compromised system. This tool must be run from the command line of a system by an attacker.
Detection coverage
- 2 YARA rules
Detection rules
- VOLEXITY_Apt_Malware_Win_Deepdata_Module (yara-rule)
- MALPEDIA_Win_Deepdata_Auto (yara-rule)
Reports & references
- volexity.com — Brazenbamboo Weaponizes Forticlient Vulnerability To Steal Vpn Credentials Via Deepdata (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Deepdata (report)
- blogs.blackberry.com — Lightspy Apt41 Deploys Advanced Deepdata Framework In Targeted Southern Asia Espionage Campaign (report)