PocoDown
Aliases: Blitz, PocoDownloader
- First seen
- 2018-06-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Profile updated
- 2026-07-07 15:15:55
Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications
Context
uses POCO C++ cross-platform library, Xor-based string obfuscation, SSL library code and string overlap with Xtunnel, infrastructure overlap with X-Agent, probably in use since mid-2018
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Pocodown_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Pocodown (report)
- threatvector.cylance.com — Inside The Apt28 Dll Backdoor Blitz (report)
- twitter.com — 1129653190444703744 (report)
- threatvector.cylance.com — Flirting With Ida And Apt28 (report)