YoungLotus

Aliases: DarkShare

First seen
2014-07-01 00:00:00
Malware type
backdoor, downloader
Family
Malware family
Profile updated
2026-07-07 15:27:20

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:cn

Context

Simple malware with proxy/RDP and download capabilities. It often comes bundled with installers, in particular in the Chinese realm. PE timestamps suggest that it came into existence in the second half of 2014. Some versions perform checks of the status of the internet connection (InternetGetConnectedState: MODEM, LAN, PROXY), some versions perform simple AV process-checks (CreateToolhelp32Snapshot).

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Younglotus_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Younglotus (report)
  • youtube.com — Watch (report)

External references