Maudi
- Malware type
- loader
- Profile updated
- 2026-07-07 15:11:25
Targeted industries: government-and-public-sector
Targeted regions: country_code:il
Context
Maudi is a specialized loader for the PoisonIvy RAT, typically used to gain initial access and deploy subsequent payloads. It is known to be targeted specifically at Israeli interests, often in espionage campaigns.
Detection coverage
- 1 YARA rules
Exploited vulnerabilities
- CVE-2009-3129 (vulnerability)
Detection rules
- MALPEDIA_Win_Maudi_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Maudi (report)
- contagiodump.blogspot.com — May 28 Cve 2009 3129 Xls For Office (report)
- paper.seebug.org — Normanshark Maudioperation (report)