Netskope Threat Labs

Wacatac

ATP Sandbox Adv. Heuristics

Wacatac is a heuristic detection name for trojan malware that covers a broad range of downloader and dropper behavior on Windows systems. Samples detected under this name typically arrive through phishing and malvertising, and they download follow on payloads such as stealers and backdoors. Because the name spans many campaigns, analysts should examine each detection's behavior and delivery chain individually.

First seen
January 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.Wacatac
Document-Word.Trojan.Wacatac
Linux.Trojan.Wacatac
Script-Macro.Trojan.Wacatac
Script.Trojan.Wacatac
Win32.Trojan.Wacatac
Win64.Trojan.Wacatac