Netskope Threat Labs

Graftor

ATP Sandbox Adv. HeuristicsAV

Graftor is a trojan dropper that modifies system files and downloads additional malware components onto infected Windows systems. It typically arrives through exploit driven infections and malicious documents, and its staged behavior makes it an early link in chains that deliver bankers, stealers, and backdoors. Detections under this name indicate that an installer wrote and executed new payload files on the system.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Trojan.Graftor
ByteCode-MSIL.Trojan.Graftor
Document-HTML.Trojan.Graftor
Gen:Variant.Adware.Graftor.124966
Gen:Variant.Adware.Graftor.128160
Gen:Variant.Adware.Graftor.131205
Gen:Variant.Adware.Graftor.13265
Gen:Variant.Adware.Graftor.1377
Gen:Variant.Adware.Graftor.144858
Gen:Variant.Adware.Graftor.150937