SLUB

First seen
2019-04-01 00:00:00
Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 13:09:31

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

SLUB is a malware strain known for its command-and-control communication via legitimate platforms like GitHub and Slack. It primarily targets government and technology sectors to conduct cyber espionage and maintain persistent access.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Slub_Auto (yara-rule)

Reports & references

  • Trend Micro — Who Is The Threat Actor Behind Operation Earth Kitsune (report)
  • Trend Micro — Operation Earth Kitsune A Dance Of Two New Backdoors (report)
  • virusbulletin.com — Vb2019 Lunghihorejsi (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Slub (report)
  • Trend Micro — New Slub Backdoor Uses Github Communicates Via Slack (report)
  • Trend Micro — Wp Operation Earth Kitsune (report)

External references