Red_Nue__2022__WinDealer_dealing_on_the_side_Securelist.pdf
ID: 570974c0-c4b6-47e6-8304-5019e05f883e
STIX ID: report--570974c0-c4b6-47e6-8304-5019e05f883e
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-06-06
Last Modified Date: 2022-06-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Kaspersky GReAT report examines LuoYu’s WinDealer — a modular Windows backdoor deployed via compromised auto-update flows and likely man-on-the-side interception — detailing its functionality, unusual C2 IP-generation and protocol, delivery mechanics, and providing multiple file-hash indicators; the authors conclude the actor demonstrates nation-state-level network interception capabilities and targets primarily Chinese-speaking organizations.
