Roseam

Aliases: PisLoader

First seen
2020-05-15 00:00:00
Malware type
loader
Family
Malware family
Profile updated
2026-07-07 15:18:32

Targeted industries: financial-services technology-and-telecommunications

Targeted regions: country_code:us country_code:uk country_code:ca

Context

Roseam, also known as PisLoader, is a malware family primarily used as a loader for delivering various types of payloads. It targets financial-services and technology sectors across the US, UK, and Canada, leveraging stealth techniques to evade detection.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Roseam_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Roseam (report)
  • brandefense.io — Dynamite Panda Apt Group (report)
  • researchcenter.paloaltonetworks.com — Unit42 New Wekby Attacks Use Dns Requests As Command And Control Mechanism (report)

External references