woody
- First seen
- 2017-12-01 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 15:26:29
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:ru country_code:ua
Context
Woody is a backdoor and remote access trojan (RAT) primarily used in cyber espionage campaigns targeting government and energy sectors in Eastern Europe. It is known for its advanced capabilities and links to state-sponsored threat groups.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Woody_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Woody (report)
- sans.org — Detailed Analysis Advanced Persistent Threat Malware 33814 (report)