LOWKEY
Aliases: PortReuse
- First seen
- 2021-05-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 14:26:29
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:ua country_code:ru
Context
LOWKEY, also known as PortReuse, is a modular backdoor designed to evade standard detection mechanisms by leveraging existing legitimate network connections to listen for incoming commands. It primarily targets government and energy sectors in Eastern Europe.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Lowkey_Auto (yara-rule)
Reports & references
- Mandiant — Apt41 Us State Governments (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lowkey (report)
- ESET — Eset Winnti (report)
- ESET — Winnti Group Skip2 0 Microsoft Sql Server Backdoor (report)
- Mandiant — Lowkey Hunting For The Missing Volume Serial Id (report)