HIGHNOON
- Malware type
- backdoor, loader, rootkit
- Family
- Malware family
- Profile updated
- 2026-07-07 14:27:20
Targeted industries: government-and-public-sector defense-and-aerospace
Context
According to FireEye, HIGHNOON is a backdoor that may consist of multiple components. The components may include a loader, a DLL, and a rootkit. Both the loader and the DLL may be dropped together, but the rootkit may be embedded in the DLL. The HIGHNOON loader may be designed to run as a Windows service.
Reports & references
- Mandiant — Cds19 Executive S08 Achievement Unlocked (report)
- Mandiant — Game Over Detecting And Stopping An Apt41 Operation (report)
- Mandiant — Rpt Apt41 (report)
- speakerdeck.com — Winnti Is Coming Evolution After Prosecution At Hitcon2021 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Highnoon (report)
- twitter.com — 1159461995013378048 (report)