PetitPotato

First seen
2020-05-13 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 15:03:55

Targeted industries: government-and-public-sector technology-and-telecommunications healthcare-and-pharmaceutical

Context

PetitPotato is a remote access Trojan (RAT) used for cyber espionage activities targeting multiple industries, including government, technology, and healthcare. It allows attackers to remotely execute commands and exfiltrate data from compromised systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Tool_Petitpotato (yara-rule)

Reports & references

  • labs.withsecure.com — Withsecure Andariel 2025 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Petit Potato (report)

External references