WinDealer
- First seen
- 2021-06-01 00:00:00
- Malware type
- spyware, trojan
- Family
- Malware family
- Last IoC activity
- 2026-06-17 16:55:13
- Profile updated
- 2026-07-07 13:04:03
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:hk
Context
WinDealer is an information stealer malware used by the threat actor LuoYu. It primarily targets government and technology sectors in China and Hong Kong. The malware is designed to steal sensitive data from infected systems.
Detection coverage
- 6 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Windealer_Oct_2021_2 (yara-rule)
- ARKBIRD_SOLG_MAL_Windealer_Oct_2021_1 (yara-rule)
- BLACKBERRY_Windealer_Library (yara-rule)
- BLACKBERRY_Windealer_Executable (yara-rule)
- DITEKSHEN_MALWARE_Win_Windealer (yara-rule)
- MALPEDIA_Win_Windealer_Auto (yara-rule)
Reports & references
- jsac.jpcert.or.jp — Jsac2021 301 Shui Leon En (report)
- blogs.jpcert.or.jp — Windealer (report)
- Kaspersky — 105946 (report)
- blogs.blackberry.com — Threat Thursday China Based Apt Plays Auto Updater Card To Deliver Windealer Malware (report)
- cocomelonc.github.io — Malwild Book (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Windealer (report)
- jsac.jpcert.or.jp — Jsac2022 7 Leon Niwa Ishimaru En (report)
- mssplab.github.io — Malware Analysis Windealer (report)