SkinnyBoy

First seen
2021-06-08 00:00:00
Malware type
backdoor
Profile updated
2026-07-07 15:20:12

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

SkinnyBoy is a backdoor malware used in cyber espionage campaigns, particularly targeting the government sector. It has been observed in attacks attributed to advanced persistent threat groups.

Detection coverage

  • 7 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Skinnyboy_Launcher_Jun_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Skinnyboy_Implant_Jun_2021_1 (yara-rule)
  • ARKBIRD_SOLG_MAL_Skinnyboy_Dropper_Jun_2021_1 (yara-rule)
  • CLUSTER25_APT28_Skinnyboy_Implanter (yara-rule)
  • CLUSTER25_APT28_Skinnyboy_Launcher (yara-rule)
  • SIGNATURE_BASE_APT28_Skinnyboy_Dropper_1 (yara-rule)
  • MALPEDIA_Win_Skinnyboy_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Skinnyboy (report)
  • cybergeeks.tech — Skinnyboy Apt28 (report)
  • cluster25.io — 2021 05 Fancybear (report)

External references