Netskope Threat Labs

Swrort

ATP Sandbox Adv. Heuristics

Swrort is a trojan that provides backdoor access and steals credentials on infected Windows systems. It arrives through spam attachments and loader chains, and its implant collects authentication data while maintaining a channel for operator commands. Detections under this name should trigger credential resets and a search for the delivery mechanism that installed the implant.

First seen
February 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.Swrort
Document-PDF.Backdoor.Swrort
Document-PDF.Trojan.Swrort
Document-Word.Trojan.Swrort
Script-JS.Trojan.Swrort
Script-Macro.Trojan.Swrort
Script-PowerShell.Backdoor.Swrort
Script-WScript.Backdoor.Swrort
Script-WScript.Dropper.Swrort
Script-WScript.Trojan.Swrort