Description
Redosdru is a malware family that primarily acts as a downloader, dropping the DLLs it fetches into the AppPatch directory under Program Files. It modifies the Windows registry to add persistence entries so that it runs automatically at system startup.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Alert name variants
| Alert Name |
|---|
| Win32.Downloader.Redosdru |
| Win32.Trojan.Redosdru |