logo

Regin Espionage Tool Active since 2008 | Symantec Connect

ID: 7ac541b1-916c-5a73-b057-80061e14c8fd

STIX ID: report--7ac541b1-916c-5a73-b057-80061e14c8fd

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2014-11-24

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Symantec published research on the Regin malware family, describing a sophisticated, multi-stage, encrypted backdoor active since 2008 that has been used for stealthy surveillance of private and public organizations (including telecommunications firms). Regin's modular, compartmentalized design and encrypted components enable long-term, hard-to-detect espionage activity; Symantec notes it behaves opportunistically rather than as a destructive APT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.