Netskope Threat Labs

Tepfer

ATP Sandbox Adv. HeuristicsAV

Tepfer is a credential stealing family that harvests saved FTP passwords, email credentials, and other secrets from infected systems and sends them to its operators. Researchers have documented it arriving through phishing attachments and downloaders, and its operators often use the stolen FTP credentials to inject malicious code into websites the victims maintain.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Infostealer.Tepfer
ByteCode-MSIL.Trojan.Tepfer
Trojan.Pws.Tepfer.A
Trojan.Pws.Tepfer.AC
Trojan.PWS.Tepfer.AE
Trojan.PWS.Tepfer.AH
Win32.Infostealer.Tepfer
Win32.Trojan.Tepfer