Description
ROADSWEEP is a backdoor associated with state sponsored actors that gives operators remote access and data collection capabilities on compromised systems. Detections under this name indicate targeted activity, including staged delivery through malicious documents and installed implants that support surveillance. Analysts should treat the family as part of an espionage intrusion rather than commodity criminal malware.
Stats
- First seen
- December 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
15 techniques across 6 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
TA0040 Impact
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Win32.Ransomware.Roadsweep |