Netskope Threat Labs

Fochi

ATP Sandbox Adv. HeuristicsAV

Fochi is a .NET-based trojan that targets Windows systems for data theft and remote access.

First seen
February 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.Fochi
DeepScan:Generic.Fochi.MSIL.5.35FB0392
DeepScan:Generic.Fochi.MSIL.5.74BC1654
DeepScan:Generic.Fochi.MSIL.5.BA8E878C
Dump:Generic.Fochi.MSIL.5.74BC1654
Dump:Generic.Fochi.MSIL.5.939FDE9F
Dump:Generic.Fochi.MSIL.5.BA8E878C
Gen:Variant.Application.Fochi.12
Gen:Variant.Application.Fochi.15
Gen:Variant.Application.Fochi.3