TONERJAM

Malware type
backdoor
Profile updated
2026-07-07 13:11:15

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:tw country_code:hk country_code:vn

Context

According to Symantec, Grager was deployed against three organizations in Taiwan, Hong Kong, and Vietnam in April 2024. Analysis of the backdoor revealed that it used the Graph API to communicate with a C&C server hosted on Microsoft OneDrive. Grager was downloaded from a typosquatted URL mimicking the open-source file archiver 7-Zip.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Tonerjam_Auto (yara-rule)

Reports & references

  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
  • cloud.google.com — Ivanti Post Exploitation Lateral Movement (report)
  • security.com — Cloud Espionage Attacks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Tonerjam (report)

External references