Netskope Threat Labs

Downeks

ATP Sandbox Adv. Heuristics

Downeks is a backdoor used by the Molerats threat actor in campaigns against government and telecommunications organizations, documented alongside the group's use of the QuasarRAT tool.

First seen
May 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.Downeks
Win32.Trojan.Downeks