Furtim
- First seen
- 2016-05-01 00:00:00
- Malware type
- rootkit
- Family
- Malware family
- Last IoC activity
- 2026-07-15 16:45:04
- Profile updated
- 2026-07-07 15:02:21
Targeted industries: energy-and-utilities technology-and-telecommunications
Targeted regions: country_code:us country_code:ca country_code:de
Context
Furtim is a stealthy rootkit primarily targeting industrial control systems within energy and utilities sectors. It is known for its modular design and its ability to evade detection by disabling security features on infected systems.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Furtim_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Furtim (report)
- sentinelone.com — Sfg Furtims Parent (report)