Drokbk

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:53:32

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:ir

Context

Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure. This makes it difficult to detect and remove, as GitHub is not traditionally associated with malicious activities. Drokbk attacks have been linked to the Iranian APT group Nemesis Kitten. This group is believed to use Drokbk for cyberespionage and financial information theft activities.

Reports & references

  • Microsoft — Nation State Threat Actor Mint Sandstorm Refines Tradecraft To Attack High Value Targets (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Drokbk (report)
  • secureworks.com — Drokbk Malware Uses Github As Dead Drop Resolver (report)
  • esentire.com — Exploitation Of Vmware Horizon Servers By Tunnelvision Threat Actor (report)

External references