SoulSearcher

Malware type
loader
Family
Malware family
Profile updated
2026-07-07 14:42:03

Targeted industries: government-and-public-sector defense-and-aerospace technology-and-telecommunications

Context

SoulSearcher is a second-stage loader responsible for executing the Soul backdoor main module and parsing its configuration. SoulSearcher has multiple variants based on where the configuration and payload are located and on the type of configuration.

Reports & references

  • research.checkpoint.com — Pandas With A Soul Chinese Espionage Attacks Against Southeast Asian Government Entities (report)
  • fortinet.com — Unraveling The Evolution Of The Soul Searcher Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Soulsearcher (report)

External references