Edam

Aliases: SECONDBEST

Malware type
dropper, downloader
Profile updated
2026-07-07 14:59:32

Context

According to Orange Cyberdefense, Edam is written in C++ and its PDB path indicates it is called "droper_dll". It is capable of establishing persistence by setting up a Run key as Setting App which points towards its own file and then of downloading from another C2 a final stage using HTTP GET.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Edam_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Edam (report)
  • strikeready.com — Ru Apt Targeting Energy Infrastructure Unknown Unknowns Part 3 (report)
  • github.com — Edam (report)

External references