Heriplor

First seen
2020-11-15 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 12:44:21

Targeted industries: government-and-public-sector financial-services energy-and-utilities

Targeted regions: country_code:ru country_code:us

Context

Heriplor is a remote access trojan (RAT) used primarily for cyber-espionage activities. It has been observed targeting critical infrastructure sectors and government entities, with capabilities including data exfiltration and remote command execution.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Heriplor_Auto (yara-rule)

Reports & references

  • Broadcom/Symantec — Dragonfly Energy Sector Cyber Attacks (report)
  • Broadcom/Symantec — Dragonfly Western Energy Sector Targeted Sophisticated Attack Group (report)
  • vblocalhost.com — Vb2021 Slowik (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Heriplor (report)
  • insights.sei.cmu.edu — Api Hashing Tool Imagine That (report)

External references