Netskope Threat Labs

VaporRage

ATP Sandbox Adv. Heuristics

VaporRage is a shellcode downloader that cyberattackers associated with APT29 have used since at least 2021. It fetches shellcode stages and executes them in memory, and its use as a downloader means detections usually signal an early stage of a staged intrusion rather than the operation's final payload.

First seen
March 2022
Last seen
September 2026
Vaporrage

4 techniques across 2 tactics.

TA0005 Stealth

  • T1140Deobfuscate/Decode Files or Information
  • T1480Execution Guardrails

TA0011 Command and Control

Alert Name
Shortcut.Downloader.VaporRage
Win32.Downloader.VaporRage
Win32.Trojan.VaporRage
Win64.Downloader.VaporRage
Win64.Trojan.Vaporrage
Win64.Trojan.VaporRage