Drokbk
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 12:53:32
Targeted industries: financial-services government-and-public-sector
Targeted regions: country_code:ir
Context
Drokbk stands out for its use of the GitHub platform as part of its C&C infrastructure. This makes it difficult to detect and remove, as GitHub is not traditionally associated with malicious activities. Drokbk attacks have been linked to the Iranian APT group Nemesis Kitten. This group is believed to use Drokbk for cyberespionage and financial information theft activities.
Reports & references
- Microsoft — Nation State Threat Actor Mint Sandstorm Refines Tradecraft To Attack High Value Targets (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Drokbk (report)
- secureworks.com — Drokbk Malware Uses Github As Dead Drop Resolver (report)
- esentire.com — Exploitation Of Vmware Horizon Servers By Tunnelvision Threat Actor (report)