shadowhammer

Aliases: DAYJOB

First seen
2019-01-01 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 12:54:00

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:hk country_code:tw country_code:kr country_code:gb country_code:au country_code:us

Context

ShadowHammer is a targeted attack campaign that compromised a popular software update mechanism to distribute malware. It specifically targeted users across multiple regions, focusing on organizations in the technology and telecommunications sectors. The attack vector involved a sophisticated supply chain compromise.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Shadowhammer_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Kaspersky — 89992 (report)
  • Kaspersky — 97937 (report)
  • ESET — Eset Winnti (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Shadowhammer (report)
  • vkremez.com — Lets Learn Dissecting Operation (report)
  • blog.reversinglabs.com — Forging The Shadowhammer (report)
  • blog.f-secure.com — A Hammer Lurking In The Shadows (report)
  • labsblog.f-secure.com — A Hammer Lurking In The Shadows (report)
  • countercept.com — Analysis Shadowhammer Asus Attack First Stage Payload (report)
  • norfolkinfosec.com — Possible Shadowhammer Targeting Low Confidence (report)
  • mauronz.github.io — Shadowhammer Backdoor (report)
  • Kaspersky — 90380 (report)
  • skylightcyber.com — Unleash The Hash Shadowhammer Mac List (report)
  • youtube.com — Watch (report)
  • norfolkinfosec.com — The First Stage Of Shadowhammer (report)
  • Trend Micro — Analyzing C C Runtime Library Code Tampering In Software Supply Chain Attacks (report)

External references