shadowhammer
Aliases: DAYJOB
- First seen
- 2019-01-01 00:00:00
- Malware type
- backdoor
- Profile updated
- 2026-07-07 12:54:00
Targeted industries: technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:hk country_code:tw country_code:kr country_code:gb country_code:au country_code:us
Context
ShadowHammer is a targeted attack campaign that compromised a popular software update mechanism to distribute malware. It specifically targeted users across multiple regions, focusing on organizations in the technology and telecommunications sectors. The attack vector involved a sophisticated supply chain compromise.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Shadowhammer_Auto (yara-rule)
Reports & references
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Kaspersky — 89992 (report)
- Kaspersky — 97937 (report)
- ESET — Eset Winnti (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Shadowhammer (report)
- vkremez.com — Lets Learn Dissecting Operation (report)
- blog.reversinglabs.com — Forging The Shadowhammer (report)
- blog.f-secure.com — A Hammer Lurking In The Shadows (report)
- labsblog.f-secure.com — A Hammer Lurking In The Shadows (report)
- countercept.com — Analysis Shadowhammer Asus Attack First Stage Payload (report)
- norfolkinfosec.com — Possible Shadowhammer Targeting Low Confidence (report)
- mauronz.github.io — Shadowhammer Backdoor (report)
- Kaspersky — 90380 (report)
- skylightcyber.com — Unleash The Hash Shadowhammer Mac List (report)
- youtube.com — Watch (report)
- norfolkinfosec.com — The First Stage Of Shadowhammer (report)
- Trend Micro — Analyzing C C Runtime Library Code Tampering In Software Supply Chain Attacks (report)