Desktop

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-20 12:23:21
Profile updated
2026-07-07 16:17:06

Targeted industries: healthcare-and-pharmaceutical education-and-nonprofits government-and-public-sector

Context

Desktop is a ransomware family known for encrypting files on infected machines and demanding a ransom for decryption. It targets various sectors, emphasizing healthcare, education, and public governance systems.

Detection coverage

  • 4 YARA rules

Used by threat actors

  • Emerald Sleet PowerShell User Execution Activity (campaign)
  • FIN12 March 2023 Hospital Center Intrusion (campaign)
  • Kimsuky Remote Desktop Access Activity (campaign)
  • Midnight Blizzard RDP File Spearphishing Campaign (campaign)

Detection rules

  • SECUINFRA_MALWARE_Plugx_USB_Delivery_Ini_Icon_Jun23 (yara-rule)
  • SECUINFRA_MALWARE_Plugx_USB_Delivery_Ini_Recbin_Jun23 (yara-rule)
  • DITEKSHEN_INDICATOR_RMM_Pulseway_Remotedesktop (yara-rule)
  • SIGNATURE_BASE_HKTL_NET_GUID_P2P (yara-rule)