Speculoos

Malware type
backdoor
Family
Malware family
Profile updated
2026-07-07 12:57:01

Targeted industries: technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us country_code:nl country_code:fr

Context

Speculoos is a backdoor malware primarily targeting technology, telecommunications, and government sectors. It emerged in late 2020, leveraging vulnerabilities to infiltrate systems and maintain persistent access.

Detection coverage

  • 1 YARA rules

Detection rules

  • SIGNATURE_BASE_APT_APT41_CN_ELF_Speculoos_Backdoor (yara-rule)

Reports & references

  • secureworks.com — Bronze Atlas (report)
  • Palo Alto Unit 42 — Apt41 Using New Speculoos Backdoor To Target Organizations Globally (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Speculoos (report)
  • Mandiant — Apt41 Initiates Global Intrusion Campaign Using Multiple Exploits (report)

External references