Saitama Backdoor

Aliases: AMATIAS, Saitama

First seen
2021-06-15 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 15:08:09

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Context

This in .Net witten backdoor abuses the DNS protocoll for its C2 communication. Also other techniques (e.g. long random sleeps, compression) are used to become more stealthy.

Detection coverage

  • 2 YARA rules

Detection rules

  • SEKOIA_Apt_Oilrig_Saitama_Backdoor_May2022 (yara-rule)
  • SEKOIA_Apt_Oilrig_Saitama_Backdoor_May2022_2 (yara-rule)

Reports & references

  • Trend Micro — New Apt34 Malware Targets The Middle East (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Saitama (report)
  • blog.malwarebytes.com — Apt34 Targets Jordan Government Using New Saitama Backdoor (report)
  • isc.sans.edu — 28738 (report)
  • x-junior.github.io — Apt34 (report)
  • fortinet.com — Please Confirm You Received Our Apt (report)

External references