Netskope Threat Labs

Symmi

ATP Sandbox Adv. HeuristicsAV

Symmi is a worm that spreads through network shares and removable drives while providing backdoor access to infected systems. Its propagation copies itself to shared storage so that infections move with users and media, and its backdoor component accepts operator commands and downloads additional payloads. Detections under this name indicate worm activity, so responders should audit shared drives and connected devices.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Trojan.Symmi
Document-HTML.Trojan.Symmi
Gen:Variant.Adware.ICloader.Symmi.40
Gen:Variant.Adware.ICloader.Symmi.51
Gen:Variant.Adware.Rukometa.Symmi.2
Gen:Variant.Adware.Symmi.10406
Gen:Variant.Adware.Symmi.10796
Gen:Variant.Adware.Symmi.11285
Gen:Variant.Adware.Symmi.1877
Gen:Variant.Adware.Symmi.19008