DoubleFantasy (Windows)

Aliases: VALIDATOR

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:58:32

Targeted industries: government-and-public-sector

Targeted regions: country_code:ir

Context

DoubleFantasy, also known as VALIDATOR, is a backdoor used primarily for initial reconnaissance and validation of targets. It is associated with cyber-espionage activities, particularly linked to threats targeting the government sector.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Apt_Kimsuky_Validator_Strings (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Doublefantasy (report)
  • twitter.com — 1294565186939092994 (report)
  • fmnagisa.wordpress.com — Revisiting Equationgroups Fanny Worm Or Dementiawheel (report)
  • Kaspersky — 68750 (report)

External references