Heriplor
- First seen
- 2020-11-15 00:00:00
- Malware type
- rat
- Family
- Malware family
- Profile updated
- 2026-07-07 12:44:21
Targeted industries: government-and-public-sector financial-services energy-and-utilities
Targeted regions: country_code:ru country_code:us
Context
Heriplor is a remote access trojan (RAT) used primarily for cyber-espionage activities. It has been observed targeting critical infrastructure sectors and government entities, with capabilities including data exfiltration and remote command execution.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Heriplor_Auto (yara-rule)
Reports & references
- Broadcom/Symantec — Dragonfly Energy Sector Cyber Attacks (report)
- Broadcom/Symantec — Dragonfly Western Energy Sector Targeted Sophisticated Attack Group (report)
- vblocalhost.com — Vb2021 Slowik (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Heriplor (report)
- insights.sei.cmu.edu — Api Hashing Tool Imagine That (report)