yayih
Aliases: aumlib, bbsinfo
- First seen
- 2010-05-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Last IoC activity
- 2026-05-02 03:39:27
- Profile updated
- 2026-07-07 15:27:16
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:jp
Context
Yayih is a remote access trojan (RAT) known for targeting governmental and telecommunications sectors, particularly in East Asia. It is associated with cyber espionage activities and is believed to be operated by threat actors based in Asia.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Yayih_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Yayih (report)
- Mandiant — Survival Of The Fittest New York Times Attackers Evolve Quickly (report)