Sarhust

Aliases: ENDCMD, Hussarini

First seen
2012-05-15 00:00:00
Malware type
rat, spyware
Family
Malware family
Profile updated
2026-07-07 15:06:36

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:ru

Context

Sarhust, also known as ENDCMD or Hussarini, is a remote access tool used primarily for espionage and data theft. It targets financial institutions and government sectors with capabilities to exfiltrate sensitive information and perform unauthorized actions on infected systems.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Sarhust_Auto (yara-rule)

Reports & references

  • speakerdeck.com — Into The Fog The Return Of Icefog Apt (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sarhust (report)
  • fortinet.com — Hussarini Targeted Cyber Attack In The Philippines (report)
  • Trend Micro — Bkdr Sarhust.A (report)

External references