Netskope Threat Labs

Volgmer

ATP Sandbox Adv. Heuristics

Volgmer is a backdoor trojan designed to provide covert access to compromised systems, used since at least 2013 against government, financial, automotive, and media targets, with spearphishing as its suspected primary delivery mechanism.

First seen
February 2022
Last seen
September 2026

19 techniques across 6 tactics.

TA0002 Execution

TA0003 Persistence

TA0005 Stealth

TA0007 Discovery

  • T1007System Service Discovery
  • T1012Query Registry
  • T1016System Network Configuration Discovery
  • T1049System Network Connections Discovery
  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0011 Command and Control

TA0112 Defense Impairment

Alert Name
Win32.Backdoor.Volgmer
Win32.Trojan.Volgmer