SaiGon

First seen
2020-05-15 00:00:00
Malware type
backdoor
Last IoC activity
2026-07-03 13:29:42
Profile updated
2026-07-07 14:58:56

Targeted industries: financial-services

Context

FireEye reports SaiGon as a variant of ISFB v3 (versions documented are tagged 3.50.132) that is more a generic backdoor than being focused on enabling banking fraud.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Saigon_Auto (yara-rule)

Reports & references

  • research.checkpoint.com — Gozi The Malware With A Thousand Faces (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Saigon (report)
  • Mandiant — Saigon Mysterious Ursnif Fork (report)

External references