Redosdru

Malware type
downloader
Family
Malware family
Last IoC activity
2026-07-21 22:51:30
Profile updated
2026-07-07 15:17:44

Context

Redosdru is a malware family that primarily acts as a downloader. Upon execution, it may drop downloaded DLLs in the "%ProgramFiles%\AppPatch" directory. The malware modifies the Windows registry to ensure its persistence, adding entries to run automatically at system startup.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Redosdru (report)
  • medium.com — Reverse Engineering Redosdru String Decryption 595599087Dbb (report)
  • securitynews.sonicwall.com — Redosdru V Malware That Hides In Encrypted Dll Files To Avoid Detection By Firewalls May 112016 (report)

External references