mozart

First seen
2020-02-01 00:00:00
Malware type
loader
Family
Malware family
Profile updated
2026-07-07 15:12:44

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Context

According to PCrisk, Mozart is malicious software that allows attackers (cyber criminals) to execute various commands on an infected computer through the DNS protocol. This communication method helps cyber criminals to avoid detection via security software. Mozart is categorized as a malware loader and executes commands that cause download and installation of malicious software.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Mozart_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Mozart (report)
  • github.com — 2015 01 11 The Mozart Ram Scraper.Md (report)
  • securitykitten.github.io — The Mozart Ram Scraper (report)

External references