Netskope Threat Labs

Leonem

ATP Sandbox Adv. Heuristics

Leonem is a trojan that steals credentials and provides remote access capabilities to cyberattackers on infected systems. Detections under this name indicate that an implant collected authentication data and maintained a channel for operator commands, and the family's campaigns frequently pair it with phishing infrastructure. Analysts should treat Leonem detections as part of a broader intrusion rather than an isolated infection.

First seen
July 2022
Last seen
October 2026
Alert Name
ByteCode-JAVA.Trojan.Leonem
ByteCode-MSIL.Trojan.Leonem
Document-Excel.Trojan.Leonem
Document-HTML.Trojan.Leonem
Document-Office.Trojan.Leonem
Document-OLE.Trojan.Leonem
Document-PDF.Trojan.Leonem
Document-RTF.Trojan.Leonem
Document-Word.Trojan.Leonem
Email-MIME.Trojan.Leonem