EtumBot

Aliases: HighTide

First seen
2011-02-01 00:00:00
Malware type
botnet, loader
Family
Malware family
Profile updated
2026-07-07 12:35:41

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp

Context

EtumBot, also known as HighTide, is a malware family associated with espionage activities primarily targeting government and technology sectors in East Asia. It functions as a botnet with capabilities for command and control communication and malware distribution.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Etumbot_Auto (yara-rule)

Reports & references

  • Mandiant — Darwins Favorite Apt Group 2 (report)
  • secureworks.com — Bronze Globe (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Etumbot (report)
  • zscaler.com — Cnacom Open Source Exploitation Strategic Web Compromise (report)

External references