LDR4

Malware type
backdoor
Family
Malware family
Last IoC activity
2026-06-27 05:54:35
Profile updated
2026-07-07 15:09:25

Context

A further branch of the URSNIF collection of malware families. According to Mandiant, it no longer has focus on banking fraud but generic backdoor capabilities instead.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Ursnif_Ldr4 (yara-rule)
  • MALPEDIA_Win_Ldr4_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Ldr4 (report)
  • Mandiant — Rm3 Ldr4 Ursnif Banking Fraud (report)

External references