Desktop
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-20 12:23:21
- Profile updated
- 2026-07-07 16:17:06
Targeted industries: healthcare-and-pharmaceutical education-and-nonprofits government-and-public-sector
Context
Desktop is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption. It targets various sectors, emphasizing healthcare, education, and public governance systems.
Detection coverage
- 4 YARA rules
Used by threat actors
- Emerald Sleet PowerShell User Execution Activity (campaign)
- FIN12 March 2023 Hospital Center Intrusion (campaign)
- Kimsuky Remote Desktop Access Activity (campaign)
- Midnight Blizzard RDP File Spearphishing Campaign (campaign)
Detection rules
- SECUINFRA_MALWARE_Plugx_USB_Delivery_Ini_Icon_Jun23 (yara-rule)
- SECUINFRA_MALWARE_Plugx_USB_Delivery_Ini_Recbin_Jun23 (yara-rule)
- DITEKSHEN_INDICATOR_RMM_Pulseway_Remotedesktop (yara-rule)
- SIGNATURE_BASE_HKTL_NET_GUID_P2P (yara-rule)