Pterois

Malware type
loader
Profile updated
2026-07-07 13:15:37

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

According to Seqrite, this is a loader for a follow-up side-loaded and in memory-staged Cobalt Strike Beacon. It uses API hashing (SDBM) and pulls the next stage from Google Drive using hardcoded access credentials.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Pterois_Auto (yara-rule)

Reports & references

  • seqrite.com — Swan Vector Apt Targeting Taiwan Japan Dll Implants (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Pterois (report)

External references