PeddleCheap
- First seen
- 2017-04-14 00:00:00
- Malware type
- backdoor
- Last IoC activity
- 2026-07-19 00:05:57
- Profile updated
- 2026-07-07 15:00:14
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks. In May 2020, ESET mentioned that they found mysterious samples of PeddleCheap packed with a custom packer so far exclusively attributed to Winnti.
Reports & references
- research.checkpoint.com — A Deep Dive Into Doublefeature Equation Groups Post Exploitation Dashboard (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Peddlecheap (report)
- twitter.com — 1258353960781598721 (report)
- obscuritylabs.com — Match Made In The Shadows Part 3 (report)
- forcepoint.com — New Whitepaper Danderspritzpeddlecheap Traffic Analysis Part 1 2 (report)