Sheriff
- Malware type
- backdoor
- Profile updated
- 2026-07-07 14:57:29
Targeted industries: defense-and-aerospace
Targeted regions: country_code:ua
Context
According to IBM X-Force, this is a modular backdoor that was used for targeting the defense sector of Ukraine. It uses the Dropbox API for C2 and data exfiltration.
Reports & references
- ibm.com — X Force Discovers New Sheriff Backdoor Target Ukraine (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sheriff (report)