Deprimon
- First seen
- 2017-03-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Profile updated
- 2026-07-07 14:57:25
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:de country_code:cz
Context
According to ESET Research, DePriMon is a malicious downloader, with several stages and using many non-traditional techniques. To achieve persistence, the malware registers a new local port monitor – a trick falling under the “Port Monitors” technique in the MITRE ATT&CK knowledgebase. For that, the malware uses the “Windows Default Print Monitor” name; that’s why we have named it DePriMon. Due to its complexity and modular architecture, researcher believe it to be a framework. DePriMon has been active since at least March 2017. DePriMon was detected in a private company, based in Central Europe, and at dozens of computers in the Middle East.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Deprimon (report)
- ESET — Deprimon Default Print Monitor Malicious Downloader (report)