LOWKEY

Aliases: PortReuse

First seen
2021-05-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 14:26:29

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:ua country_code:ru

Context

LOWKEY, also known as PortReuse, is a modular backdoor designed to evade standard detection mechanisms by leveraging existing legitimate network connections to listen for incoming commands. It primarily targets government and energy sectors in Eastern Europe.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Lowkey_Auto (yara-rule)

Reports & references

  • Mandiant — Apt41 Us State Governments (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lowkey (report)
  • ESET — Eset Winnti (report)
  • ESET — Winnti Group Skip2 0 Microsoft Sql Server Backdoor (report)
  • Mandiant — Lowkey Hunting For The Missing Volume Serial Id (report)

External references