Netskope Threat Labs

Mabezat

ATP Sandbox Adv. HeuristicsAV

Mabezat is a self replicating worm family that spread through network shares and USB drives in the late 2000s. It infected executable files, archived stolen documents into password protected files for exfiltration, and shut down security tools, which made cleanup on shared networks difficult.

First seen
March 2022
Last seen
September 2026
Alert Name
Win32.Virus.Mabezat
Win32.Worm.Mabezat
Win32.Worm.Mabezat.D
Win32.Worm.Mabezat.F
Win32.Worm.Mabezat.G
Win32.Worm.Mabezat.Gen
Win32.Worm.Mabezat.S
Win64.Trojan.Mabezat