REDSHAWL

Malware type
trojan
Profile updated
2026-07-07 12:46:01

Context

REDSHAWL is a session hijacking utility that starts a new process as another user currently logged on to the same system via command-line.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Redshawl_Auto (yara-rule)

Reports & references

  • Kaspersky — 77908 (report)
  • Mandiant — Rpt Apt38 (report)
  • virusbulletin.com — Vb2018 Kalnai Poslusny (report)
  • media.kasperskycontenthub.com — Lazarus Under The Hood Pdf Final (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Redshawl (report)

External references