WinDealer

First seen
2021-06-01 00:00:00
Malware type
spyware, trojan
Family
Malware family
Last IoC activity
2026-06-17 16:55:13
Profile updated
2026-07-07 13:04:03

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:hk

Context

WinDealer is an information stealer malware used by the threat actor LuoYu. It primarily targets government and technology sectors in China and Hong Kong. The malware is designed to steal sensitive data from infected systems.

Detection coverage

  • 6 YARA rules

Detection rules

  • ARKBIRD_SOLG_MAL_Windealer_Oct_2021_2 (yara-rule)
  • ARKBIRD_SOLG_MAL_Windealer_Oct_2021_1 (yara-rule)
  • BLACKBERRY_Windealer_Library (yara-rule)
  • BLACKBERRY_Windealer_Executable (yara-rule)
  • DITEKSHEN_MALWARE_Win_Windealer (yara-rule)
  • MALPEDIA_Win_Windealer_Auto (yara-rule)

Reports & references

  • jsac.jpcert.or.jp — Jsac2021 301 Shui Leon En (report)
  • blogs.jpcert.or.jp — Windealer (report)
  • Kaspersky — 105946 (report)
  • blogs.blackberry.com — Threat Thursday China Based Apt Plays Auto Updater Card To Deliver Windealer Malware (report)
  • cocomelonc.github.io — Malwild Book (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Windealer (report)
  • jsac.jpcert.or.jp — Jsac2022 7 Leon Niwa Ishimaru En (report)
  • mssplab.github.io — Malware Analysis Windealer (report)

External references