Netskope Threat Labs

ROADSWEEP

ATP Sandbox Adv. Heuristics

ROADSWEEP is a backdoor associated with state sponsored actors that gives operators remote access and data collection capabilities on compromised systems. Detections under this name indicate targeted activity, including staged delivery through malicious documents and installed implants that support surveillance. Analysts should treat the family as part of an espionage intrusion rather than commodity criminal malware.

First seen
December 2022
Last seen
October 2026

15 techniques across 6 tactics.

TA0002 Execution

  • T1059Command and Scripting Interpreter
  • T1559Inter-Process Communication

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1083File and Directory Discovery
  • T1120Peripheral Device Discovery
  • T1680Local Storage Discovery

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Win32.Ransomware.Roadsweep