logo

Red_Nue__2022__WinDealer_dealing_on_the_side_Securelist.pdf

ID: 570974c0-c4b6-47e6-8304-5019e05f883e

STIX ID: report--570974c0-c4b6-47e6-8304-5019e05f883e

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2022-06-06

Last Modified Date: 2022-06-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky GReAT report examines LuoYu’s WinDealer — a modular Windows backdoor deployed via compromised auto-update flows and likely man-on-the-side interception — detailing its functionality, unusual C2 IP-generation and protocol, delivery mechanics, and providing multiple file-hash indicators; the authors conclude the actor demonstrates nation-state-level network interception capabilities and targets primarily Chinese-speaking organizations.