Saitama Backdoor
Aliases: AMATIAS, Saitama
- First seen
- 2021-06-15 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Profile updated
- 2026-07-07 15:08:09
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services
Context
This in .Net witten backdoor abuses the DNS protocoll for its C2 communication. Also other techniques (e.g. long random sleeps, compression) are used to become more stealthy.
Detection coverage
- 2 YARA rules
Detection rules
- SEKOIA_Apt_Oilrig_Saitama_Backdoor_May2022 (yara-rule)
- SEKOIA_Apt_Oilrig_Saitama_Backdoor_May2022_2 (yara-rule)
Reports & references
- Trend Micro — New Apt34 Malware Targets The Middle East (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Saitama (report)
- blog.malwarebytes.com — Apt34 Targets Jordan Government Using New Saitama Backdoor (report)
- isc.sans.edu — 28738 (report)
- x-junior.github.io — Apt34 (report)
- fortinet.com — Please Confirm You Received Our Apt (report)