Netskope Threat Labs

EternalRocks

ATP Sandbox Adv. Heuristics

EternalRocks (a.k.a. MicroBotMassiveNet) is a worm that spread using the NSA-developed exploits leaked by the Shadow Brokers, and later reporting connected related infrastructure to the BackdoorDiplomacy threat actor.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.EternalRocks
Win32.Trojan.EternalRocks
Win64.Trojan.EternalRocks