RollSling

First seen
2021-04-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 12:45:54

Targeted industries: government-and-public-sector

Context

RollSling is a Remote Access Trojan (RAT) used primarily for cyber-espionage purposes, targeting government and public sector organizations. It is known for its ability to exfiltrate sensitive data and provide persistent access to compromised systems.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2023-42793 (vulnerability)

Detection rules

  • SEKOIA_Backdoor_Win_Rollsling (yara-rule)

Reports & references

  • Microsoft — Multiple North Korean Threat Actors Exploiting The Teamcity Cve 2023 42793 Vulnerability (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Roll Sling (report)

External references