Emdivi

Malware type
rat
Family
Malware family
Last IoC activity
2026-07-15 20:45:03
Profile updated
2026-07-07 14:33:47

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:jp

Context

Emdivi is a remote access trojan primarily targeting Japanese organizations. It's known for being used by advanced persistent threat groups to conduct espionage, particularly against government and technology sectors.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Emdivi_Auto (yara-rule)

Reports & references

  • virusbulletin.com — Vb2019 Paper Apt Cases Exploiting Vulnerabilities Regionspecific Software (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Emdivi (report)
  • macnica.net — Security Report 20160613 (report)
  • Trend Micro — Chessmaster Cyber Espionage Campaign (report)
  • Kaspersky — 71876 (report)
  • Trend Micro — Attackers Target Organizations In Japan Transform Local Sites Into Cc Servers For Emdivi Backdoor (report)
  • blog.jpcert.or.jp — Decrypting Strings In Emdivi (report)

External references