QUICKMUTE

First seen
2022-05-15 00:00:00
Malware type
downloader, loader
Profile updated
2026-07-07 15:17:06

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

QuickMute is a malware developed using the C/C++ programming language. Functionally provides download, RC4 decryption, and in-memory launch of the payload (waiting for a PE file with the export function "HttpsVictimMain"). To communicate with the management server, a number of protocols are provided, in particular: TCP, UDP, HTTP, HTTPS.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Quickmute_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Quickmute (report)
  • CERT-UA — 375404 (report)

External references