Wslink

Aliases: FinickyFrogfish

Malware type
loader, backdoor
Family
Malware family
Profile updated
2026-07-07 15:26:37

Targeted industries: technology-and-telecommunications defense-and-aerospace

Context

Wslink, also known as FinickyFrogfish, is a sophisticated loader and backdoor malware used by advanced persistent threat actors. It is capable of executing various payloads in memory and has been observed targeting high-value sectors, such as technology and defense, with a focus on stealth and persistence.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Wslink_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Wslink (report)
  • ESET — Eset Wsliknkvm (report)
  • twitter.com — 1453342652682981378 (report)
  • ESET — Wslink Unique Undocumented Malicious Loader Runs Server (report)

External references