Murofet
Aliases: Licat
- First seen
- 2010-06-01 00:00:00
- Malware type
- botnet, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-06-09 05:56:43
- Profile updated
- 2026-07-07 12:59:47
Targeted industries: financial-services
Context
According to bin.re, Murofet, also called LICAT, is a member of the ZeuS family. It uses a Domain Generation Algorithm (DGA) to determine the current C2 domain names.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Murofet_Auto (yara-rule)
Reports & references
- secureworks.com — Evolution Of The Gold Evergreen Threat Group (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 008 (report)
- cert.ssi.gouv.fr — 20220427 Np Tlpwhite Anssi Fin7 (report)
- bin.re — Three Variants Of Murofets Dga (report)
- wired.com — Russian Hacker Spy Botnet (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Murofet (report)