Description
Sakula (a.k.a. Viper, Sakurel) is a backdoor associated with the Deep Panda threat group that targets Windows systems for remote access and data exfiltration through encrypted payloads. It reached victims through watering hole attacks on targeted websites and malicious downloads, and its operators favored quiet, persistent access to collect intelligence. The family's campaigns against technology and think tank targets made it a marker of Chinese state sponsored espionage in the 2010s.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Also known as
SakurelViper
MITRE ATT&CK techniques
11 techniques across 5 tactics.
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
Associated groups
Alert name variants
| Alert Name |
|---|
| CMD:Heur.BZC.PZQ.Viper.4.4DC18938 |
| CMD:Heur.BZC.PZQ.Viper.4.D5BF9750 |
| CMD:Heur.BZC.PZQ.Viper.4.F76300ED |
| Heur.BZC.PZQ.Viper.4.071536E5 |
| Heur.BZC.PZQ.Viper.4.0822DC20 |
| Heur.BZC.PZQ.Viper.4.1496E17B |
| Heur.BZC.PZQ.Viper.4.15E6C41F |
| Heur.BZC.PZQ.Viper.4.15E91EF6 |
| Heur.BZC.PZQ.Viper.4.168E9CB5 |
| Heur.BZC.PZQ.Viper.4.17DE85F7 |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Sakula.Generic suspicious traffic detected |