SHAPESHIFT

First seen
2021-03-15 00:00:00
Malware type
trojan, ransomware
Family
Malware family
Profile updated
2026-07-07 12:42:23

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:us country_code:ru

Context

SHAPESHIFT is a sophisticated malware family primarily targeting financial services and government sectors in the United States and Russia. It is known for its trojan and ransomware capabilities, often used in targeted attacks to gain unauthorized access and encrypt sensitive data.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Shapeshift_Auto (yara-rule)

Reports & references

  • Mandiant — Apt33 Insights Into Iranian Cyber Espionage (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Shapeshift (report)

External references