FK_Undead

Aliases: Undead

Malware type
trojan, rootkit
Family
Malware family
Profile updated
2026-07-07 15:01:37

Context

This malware family is mainly spread through various private server clients in bundles, and mainly tamper with user system network data packets through technical means such as TDI filtering, DNS hijacking, HTTP(s) injection, and HOSTS redirection, hijacking normal web page access to designated private server websites, and using security software cloud detection and killing data packet shielding, shutdown callback rewriting and other means to achieve counter-detection.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Fk_Undead_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Fk Undead (report)
  • gslab.qq.com — Article 663 1 (report)

External references