XDSpy

First seen
2011-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:59:30

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:by country_code:pl country_code:ua country_code:rs

Context

Rare is the APT group that goes largely undetected for nine years, but XDSpy is just that; a previously undocumented espionage group that has been active since 2011. It has attracted very little public attention, with the exception of an advisory from the Belarusian CERT in February 2020. In the interim, the group has compromised many government agencies and private companies in Eastern Europe and the Balkans.

Reports & references

  • ESET — Xdspy Stealing Government Secrets Since 2011 (report)
  • vblocalhost.com — Vb2020 Faou Labelle (report)
  • github.com — Xdspy (report)

External references