Rozena

Malware type
rat
Family
Malware family
Last IoC activity
2026-07-22 01:55:25
Profile updated
2026-07-07 15:18:36

Context

Rozena is a Remote Access Trojan (RAT) that provides attackers with unauthorized access and control over affected systems. It is typically used for spying activities, data exfiltration, and command execution by leveraging compromised systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • CAPE_Rozena (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Rozena (report)
  • socinvestigation.com — Threat Actors Delivers New Rozena Backdoor With Follina Bug Detection Response (report)
  • fortinet.com — Follina Rozena Leveraging Discord To Distribute A Backdoor (report)
  • gdatasoftware.com — 35061 Server Side Polymorphism Powershell Backdoors (report)
  • gdatasoftware.com — 30862 Fileless Malware Rozena (report)

External references