Narilam

First seen
2012-10-01 00:00:00
Malware type
wiper
Profile updated
2026-07-07 15:13:08

Targeted industries: financial-services

Targeted regions: country_code:ir

Context

Narilam is a malware that targets financial databases, specifically those used in Iran. It is known for its destructive capabilities, corrupting databases by altering records.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Narilam_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Narilam (report)
  • Broadcom/Symantec — W32Narilam Business Database Sabotage (report)
  • contagiodump.blogspot.com — Nov 2012 W32Narilam Sample (report)

External references