Netskope Threat Labs

Dunihi

ATP Sandbox Adv. HeuristicsAV

Dunihi is a VBScript based trojan and worm that self propagates across networks and provides remote access capabilities to cyberattackers. It spreads through infected removable drives, network shares, and social media links, and it can download additional payloads and accept commands from its operators. The family has circulated for years in South Asian and Middle Eastern campaigns, where simple but effective VBScript tooling remains common.

First seen
April 2022
Last seen
October 2026
Alert Name
Dropped:Generic.VBS.Dunihi.1.576E9A48
Generic.VBS.Dunihi.1.626E88A8
GT:VB.Worm.Dunihi.3.589CD095
GT:VB.Worm.Dunihi.4.05AF2A84
GT:VB.Worm.Dunihi.4.14EEEB02
GT:VB.Worm.Dunihi.4.2F92F191
GT:VB.Worm.Dunihi.4.44FA144B
GT:VB.Worm.Dunihi.4.4C70B9AF
GT:VB.Worm.Dunihi.4.4E8198AF
GT:VB.Worm.Dunihi.4.6DDC05FF