PeddleCheap

First seen
2017-04-14 00:00:00
Malware type
backdoor
Last IoC activity
2026-07-19 00:05:57
Profile updated
2026-07-07 15:00:14

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks. In May 2020, ESET mentioned that they found mysterious samples of PeddleCheap packed with a custom packer so far exclusively attributed to Winnti.

Reports & references

  • research.checkpoint.com — A Deep Dive Into Doublefeature Equation Groups Post Exploitation Dashboard (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Peddlecheap (report)
  • twitter.com — 1258353960781598721 (report)
  • obscuritylabs.com — Match Made In The Shadows Part 3 (report)
  • forcepoint.com — New Whitepaper Danderspritzpeddlecheap Traffic Analysis Part 1 2 (report)

External references