Deprimon

First seen
2017-03-01 00:00:00
Malware type
downloader
Family
Malware family
Profile updated
2026-07-07 14:57:25

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:de country_code:cz

Context

According to ESET Research, DePriMon is a malicious downloader, with several stages and using many non-traditional techniques. To achieve persistence, the malware registers a new local port monitor – a trick falling under the “Port Monitors” technique in the MITRE ATT&CK knowledgebase. For that, the malware uses the “Windows Default Print Monitor” name; that’s why we have named it DePriMon. Due to its complexity and modular architecture, researcher believe it to be a framework. DePriMon has been active since at least March 2017. DePriMon was detected in a private company, based in Central Europe, and at dozens of computers in the Middle East.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Deprimon (report)
  • ESET — Deprimon Default Print Monitor Malicious Downloader (report)

External references