xxmm
Aliases: ShadowWalker
- First seen
- 2019-04-15 00:00:00
- Malware type
- rootkit, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 12:51:23
Targeted industries: technology-and-telecommunications government-and-public-sector financial-services
Targeted regions: country_code:us country_code:jp country_code:de
Context
XXMM, also known as ShadowWalker, is a sophisticated malware known for its rootkit capabilities targeting government and financial sectors. It is deployed in advanced cyber espionage campaigns.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Xxmm_Auto (yara-rule)
Reports & references
- secureworks.com — Bronze Butler Targets Japanese Businesses (report)
- secureworks.com — Bronze Butler (report)
- Trend Micro — Redbaldknight Bronze Butler Daserf Backdoor Now Using Steganography (report)
- macnica.net — Mpressioncss 2018 1H Report Mnc Rev3 Nopw (report)
- macnica.net — Feature 05 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Xxmm (report)
- cybereason.com — Labs Shadowwali New Variant Of The Xxmm Family Of Backdoors (report)
- jsac.jpcert.or.jp — Jsac2019 8 Nakatsuru En (report)