Netskope Threat Labs

Redosdru

ATP Sandbox Adv. Heuristics

Redosdru is a malware family that primarily acts as a downloader, dropping the DLLs it fetches into the AppPatch directory under Program Files. It modifies the Windows registry to add persistence entries so that it runs automatically at system startup.

First seen
March 2022
Last seen
September 2026
Alert Name
Win32.Downloader.Redosdru
Win32.Trojan.Redosdru