SeDll

First seen
2020-11-15 00:00:00
Malware type
loader, dropper
Family
Malware family
Profile updated
2026-07-07 12:52:50

Targeted industries: financial-services government-and-public-sector technology-and-telecommunications

Context

SeDll is a malware loader that is primarily used to deliver additional malicious payloads onto compromised systems. It has been observed in campaigns targeting financial, government, and tech sectors. Specific details about its operation or affiliates remain limited.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Sedll_Auto (yara-rule)

Reports & references

  • proofpoint.com — Leviathan Espionage Actor Spearphishes Maritime And Defense Targets (report)
  • Mandiant — Suspected Chinese Espionage Group Targeting Maritime And Engineering Industries (report)
  • recordedfuture.com — Chinese Threat Actor Tempperiscope (report)
  • secureworks.com — Bronze Mohawk (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sedll (report)

External references