DeliveryCheck

Aliases: CAPIBAR, GAMEDAY

First seen
2023-05-15 00:00:00
Malware type
trojan, webshell
Family
Malware family
Profile updated
2026-07-07 14:57:18

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to CERT-UA, this malware makes use of XSLT (Extensible Stylesheet Language Transformations) and COM-hijacking. Its specificity is the presence of a server part, which is usually installed on compromised MS Exchange servers in the form of a MOF (Managed Object Format) file using the Desired State Configuration (DCS) PowerShell tool), effectively turning a legitimate server into a malware control center.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Delivery Check (report)
  • CERT-UA — 5213167 (report)
  • twitter.com — 1681695399084539908 (report)

External references