GRILLMARK

Aliases: Hellsing Backdoor

First seen
2014-03-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:39:33

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:my country_code:ph

Context

This is a proxy-aware HTTP backdoor that is implemented as a service and uses the compromised system's proxy settings to access the internet. C&C traffic is base64 encoded and the files sent to the server are compressed with aPLib.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Grillmark_Auto (yara-rule)

Reports & references

  • Kaspersky — 69567 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Grillmark (report)
  • Mandiant — Rpt M Trends 2019 (report)

External references