Netskope Threat Labs

Rimecud

ATP Sandbox Adv. HeuristicsAV

Rimecud is a worm and botnet family that spread through removable drives and instant messaging links in the late 2000s. It installed a backdoor that downloaded additional malware, and cyberattackers used its botnet for spam and credential theft until coordinated takedown efforts disrupted its infrastructure.

First seen
February 2022
Last seen
September 2026
Alert Name
Gen:Variant.Rimecud.1
Gen:Variant.Rimecud.10
Gen:Variant.Rimecud.8
Script-INF.Trojan.Rimecud
Trojan.Rimecud.C
Win32.Trojan.Rimecud
Win32.Worm.Rimecud
Win32.Worm.Rimecud.AZ
Win32.Worm.Rimecud.BA