Netskope Threat Labs

Sakula

ATP Sandbox Adv. HeuristicsAVNetskope IPS

Sakula (a.k.a. Viper, Sakurel) is a backdoor associated with the Deep Panda threat group that targets Windows systems for remote access and data exfiltration through encrypted payloads. It reached victims through watering hole attacks on targeted websites and malicious downloads, and its operators favored quiet, persistent access to collect intelligence. The family's campaigns against technology and think tank targets made it a marker of Chinese state sponsored espionage in the 2010s.

First seen
May 2022
Last seen
October 2026
SakurelViper

11 techniques across 5 tactics.

TA0002 Execution

TA0003 Persistence

  • T1543Create or Modify System Process
  • T1547Boot or Logon Autostart Execution

TA0004 Privilege Escalation

  • T1548Abuse Elevation Control Mechanism

TA0005 Stealth

TA0011 Command and Control

Alert Name
CMD:Heur.BZC.PZQ.Viper.4.4DC18938
CMD:Heur.BZC.PZQ.Viper.4.D5BF9750
CMD:Heur.BZC.PZQ.Viper.4.F76300ED
Heur.BZC.PZQ.Viper.4.071536E5
Heur.BZC.PZQ.Viper.4.0822DC20
Heur.BZC.PZQ.Viper.4.1496E17B
Heur.BZC.PZQ.Viper.4.15E6C41F
Heur.BZC.PZQ.Viper.4.15E91EF6
Heur.BZC.PZQ.Viper.4.168E9CB5
Heur.BZC.PZQ.Viper.4.17DE85F7