Description
VaporRage is a shellcode downloader that cyberattackers associated with APT29 have used since at least 2021. It fetches shellcode stages and executes them in memory, and its use as a downloader means detections usually signal an early stage of a staged intrusion rather than the operation's final payload.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Also known as
Vaporrage
MITRE ATT&CK techniques
4 techniques across 2 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Shortcut.Downloader.VaporRage |
| Win32.Downloader.VaporRage |
| Win32.Trojan.VaporRage |
| Win64.Downloader.VaporRage |
| Win64.Trojan.Vaporrage |
| Win64.Trojan.VaporRage |