Sisfader

First seen
2012-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 15:47:13

Targeted industries: government-and-public-sector

Targeted regions: country_code:cn country_code:ru

Context

Sisfader is a backdoor malware used in cyber espionage campaigns. It predominantly targets government and public sector entities, with known operations in China and Russia. The malware provides remote access capabilities to attackers, allowing the exfiltration of sensitive information.

Detection coverage

  • 1 YARA rules

Exploited vulnerabilities

  • CVE-2017-8750 (vulnerability)

Detection rules

  • MALPEDIA_Win_Sisfader_Auto (yara-rule)

Reports & references

  • nao-sec.org — An Overhead View Of The Royal Road (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sisfader (report)
  • medium.com — Gobelin Panda Against The Bears 1F462D00E3A4 (report)
  • nccgroup.trust — Cve 2017 8750 Rtf And The Sisfader Rat (report)

External references