REDSALT
Aliases: Dipsind
- First seen
- 2012-05-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:17:48
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:kr country_code:jp
Context
REDSALT, also known as Dipsind, is a backdoor used primarily for cyber espionage activities. It is associated with targeted attacks on government and energy sectors, particularly in East Asia, facilitating remote access and command execution on compromised systems.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Redsalt_Auto (yara-rule)
Reports & references
- twitter.com — 1136502701301346305 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Redsalt (report)
- Mandiant — Twoforonefinal (report)
- Mandiant — Cds18 Technical S01 Hunting For Platinum (report)