PetitPotato
- First seen
- 2020-05-13 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:03:55
Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical
Context
PetitPotato is a remote access Trojan (RAT) used for cyber espionage activities targeting multiple industries, including government, technology, and healthcare. It allows attackers to remotely execute commands and exfiltrate data from compromised systems.
Detection coverage
- 1 YARA rules
Detection rules
- SEKOIA_Tool_Petitpotato (yara-rule)
Reports & references
- labs.withsecure.com — Withsecure Andariel 2025 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Petit Potato (report)