Netskope Threat Labs

Pretoria

ATP Sandbox Adv. HeuristicsAV

Pretoria refers to a toolkit that researchers have associated with espionage against South American governments, sharing infrastructure and tooling with the Machete threat actor.

First seen
April 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.Pretoria
Gen:Heur.MSIL.Pretoria.1
Win32.Trojan.Pretoria