Edam
Aliases: SECONDBEST
- Malware type
- dropper, downloader
- Profile updated
- 2026-07-07 14:59:32
Context
According to Orange Cyberdefense, Edam is written in C++ and its PDB path indicates it is called "droper_dll". It is capable of establishing persistence by setting up a Run key as Setting App which points towards its own file and then of downloading from another C2 a final stage using HTTP GET.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Edam_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Edam (report)
- strikeready.com — Ru Apt Targeting Energy Infrastructure Unknown Unknowns Part 3 (report)
- github.com — Edam (report)