xxmm

Aliases: ShadowWalker

First seen
2019-04-15 00:00:00
Malware type
rootkit, trojan
Family
Malware family
Profile updated
2026-07-07 12:51:23

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Targeted regions: country_code:us country_code:jp country_code:de

Context

XXMM, also known as ShadowWalker, is a sophisticated malware known for its rootkit capabilities targeting government and financial sectors. It is deployed in advanced cyber espionage campaigns.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Xxmm_Auto (yara-rule)

Reports & references

  • secureworks.com — Bronze Butler Targets Japanese Businesses (report)
  • secureworks.com — Bronze Butler (report)
  • Trend Micro — Redbaldknight Bronze Butler Daserf Backdoor Now Using Steganography (report)
  • macnica.net — Mpressioncss 2018 1H Report Mnc Rev3 Nopw (report)
  • macnica.net — Feature 05 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Xxmm (report)
  • cybereason.com — Labs Shadowwali New Variant Of The Xxmm Family Of Backdoors (report)
  • jsac.jpcert.or.jp — Jsac2019 8 Nakatsuru En (report)

External references