Specter

First seen
2022-01-15 00:00:00
Malware type
backdoor
Family
Malware family
Last IoC activity
2026-05-15 13:55:27
Profile updated
2026-07-07 14:30:16

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Specter is an advanced persistent threat backdoor used for espionage purposes. It primarily targets public sector and technology organizations, enabling remote access and data exfiltration.

Detection coverage

  • 1 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_ELF_Specter_Jul_2021_1 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Specter (report)
  • blog.netlab.360.com — Ghost In Action The Specter Botnet (report)
  • blog.netlab.360.com — The Pitfall Of Threat Intelligence Whitelisting Specter Botnet Is Taking Over Top Legit Dns Domains By Using Cloudns Service (report)

External references