Netskope Threat Labs

Rozena

ATP Sandbox Adv. HeuristicsAV

Rozena is a trojan that spreads through removable drives and network shares, infecting additional systems as users share storage and files. Its propagation gives cyberattackers a foothold that moves without email delivery, and it can download further payloads from remote servers. Detections under this name indicate worm style behavior, so responders should check shared storage and connected systems for the same infection.

First seen
January 2022
Last seen
October 2026
Alert Name
Backdoor.Rozena.A
ByteCode-MSIL.Trojan.Rozena
DeepScan:Generic.PWSH.Rozena.F.FFFFFFFE
DeepScan:Generic.PwShell.Rozena.1.FFFFFFFE
DeepScan:Generic.PwShell.Rozena.2.FFFFFFFE
DeepScan:Generic.PwShell.Rozena.3.FFFFFFFE
Document-PDF.Trojan.Rozena
Dump:Generic.PwShell.Rozena.1.FFFFFFFE
Dump:Generic.PwShell.Rozena.1.FFFFFFFE:80D09
Dump:Generic.PwShell.Rozena.3.FFFFFFFE