RogueRobinNET

First seen
2019-01-01 00:00:00
Malware type
backdoor, trojan
Profile updated
2026-07-07 12:53:40

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:sa country_code:qa country_code:ae

Context

RogueRobinNET is a .NET variant of the PS1.RogueRobin, known for targeting government and defense sectors in the Middle East. It functions primarily as a backdoor and trojan, allowing remote access and control over infected systems.

Reports & references

  • ti.360.net — Latest Target Attack Of Darkhydruns Group Against Middle East En (report)
  • Palo Alto Unit 42 — Darkhydrus Delivers New Trojan That Can Use Google Drive For C2 Communications (report)
  • kindredsec.com — An Overview Of Public Platform C2S (report)
  • kindredsec.wordpress.com — An Overview Of Public Platform C2S (report)
  • ptsecurity.com — Antisandbox Techniques (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Roguerobin (report)

External references