Downeks

First seen
2013-11-01 00:00:00
Malware type
downloader, dropper
Family
Malware family
Profile updated
2026-07-07 14:58:44

Targeted industries: government-and-public-sector

Context

Downeks is a malware family used by threat actors for downloading and dropping additional malicious payloads. This malware is often associated with cyber espionage activities and has been seen targeting government entities.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Downeks_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Downeks (report)
  • Palo Alto Unit 42 — Molerats Delivers Spark Backdoor (report)
  • researchcenter.paloaltonetworks.com — Unit42 Downeks And Quasar Rat Used In Recent Targeted Attacks Against Governments (report)

External references