HemiGate
- First seen
- 2023-02-15 00:00:00
- Malware type
- backdoor, rat
- Profile updated
- 2026-07-07 13:06:10
Targeted industries: government-and-public-sector energy-and-utilities financial-services
Targeted regions: country_code:us country_code:ru country_code:cn
Context
HemiGate is a sophisticated backdoor and remote access tool (RAT) utilized primarily in cyber-espionage campaigns targeting government and public sector organizations. It is known for its data exfiltration capabilities and has been detected in several high-profile intrusions.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Hemigate_Auto (yara-rule)
Reports & references
- Trend Micro — Earth Estries Targets Government Tech For Cyberespionage (report)
- jsac.jpcert.or.jp — Jsac2025 1 5 Leon Chang Theo Chen En (report)
- jsac.jpcert.or.jp — Jsac2024 1 7 Hara Nakajima Kawakami En (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hemigate (report)