Graphiron

First seen
2022-10-01 00:00:00
Malware type
downloader, spyware
Profile updated
2026-07-07 13:01:05

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

Downloader / information stealer used by UAC-0056, observed since at least October 2022.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Implant_Win_Graphiron_Downloader (yara-rule)

Reports & references

  • Broadcom/Symantec — Nodaria Ukraine Infostealer (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Graphiron (report)
  • secureworks.com — The Growing Threat From Infostealers (report)

External references