REDSALT

Aliases: Dipsind

First seen
2012-05-01 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 15:17:48

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:kr country_code:jp

Context

REDSALT, also known as Dipsind, is a backdoor used primarily for cyber espionage activities. It is associated with targeted attacks on government and energy sectors, particularly in East Asia, facilitating remote access and command execution on compromised systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Redsalt_Auto (yara-rule)

Reports & references

  • twitter.com — 1136502701301346305 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Redsalt (report)
  • Mandiant — Twoforonefinal (report)
  • Mandiant — Cds18 Technical S01 Hunting For Platinum (report)

External references