DoubleFantasy (Windows)
Aliases: VALIDATOR
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 14:58:32
Targeted industries: government-and-public-sector
Targeted regions: country_code:ir
Context
DoubleFantasy, also known as VALIDATOR, is a backdoor used primarily for initial reconnaissance and validation of targets. It is associated with cyber-espionage activities, particularly linked to threats targeting the government sector.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Apt_Kimsuky_Validator_Strings (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Doublefantasy (report)
- twitter.com — 1294565186939092994 (report)
- fmnagisa.wordpress.com — Revisiting Equationgroups Fanny Worm Or Dementiawheel (report)
- Kaspersky — 68750 (report)