DeliveryCheck
Aliases: CAPIBAR, GAMEDAY
- First seen
- 2023-05-15 00:00:00
- Malware type
- trojan, webshell
- Family
- Malware family
- Profile updated
- 2026-07-07 14:57:18
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking. Its specificity is the presence of a server part, which is usually installed on compromised MS Exchange servers in the form of a MOF (Managed Object Format) file using the Desired State Configuration (DCS) PowerShell tool), effectively turning a legitimate server into a malware control center.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Delivery Check (report)
- CERT-UA — 5213167 (report)
- twitter.com — 1681695399084539908 (report)