Retro

First seen
2019-05-20 00:00:00
Malware type
trojan, spyware
Profile updated
2026-07-07 14:42:49

Targeted industries: government-and-public-sector financial-services

Targeted regions: country_code:us country_code:ru

Context

Retro is a stealthy malware designed to evade detection while gathering sensitive information primarily from governmental and financial institutions. It often masquerades as benign software to infiltrate systems without raising suspicion.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2018-8174 (vulnerability)

Detection rules

  • MALPEDIA_Win_Retro_Auto (yara-rule)

Reports & references

  • ESET — Eset Jumping The Air Gap Wp (report)
  • blog.bushidotoken.net — Deep Dive Darkhotel Apt (report)
  • ESET — Ramsay Cyberespionage Toolkit Airgapped Networks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Retro (report)
  • blog.360totalsecurity.com — Analysis Cve 2018 8174 Vbscript 0Day Apt Actor Related Office Targeted Attack (report)

External references