Pykspa

First seen
2013-05-01 00:00:00
Malware type
worm, spyware
Family
Malware family
Last IoC activity
2026-07-22 03:54:03
Profile updated
2026-07-07 15:16:55

Context

According to Akamai, Pykspa is a worm that spreads via Skype by sending messages to other Skype users with download links. Once downloaded, Pykspa extracts personal information and communicates with its command and control servers (C2) using a domain generation algorithm (DGA).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Pykspa_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Pykspa (report)
  • youtube.com — Watch (report)
  • akamai.com — Pykspa V2 Dga Updated To Become Selective (report)
  • johannesbader.ch — The Dga Of Pykspa (report)
  • blogs.akamai.com — Pykspa V2 Dga Updated To Become Selective (report)
  • bin.re — Pykspas Inferior Dga Version (report)
  • johannesbader.ch — Pykspas Inferior Dga Version (report)
  • bin.re — The Dga Of Pykspa (report)

External references