logo

OfflRouter Malware Evades Detection in Ukraine for Almost a Decade

ID: e278669e-df52-5ec7-953f-5d49d44942bd

STIX ID: report--e278669e-df52-5ec7-953f-5d49d44942bd

Feed Name: The Hacker News

Threat Score
55/100

Date Published: 2024-04-18

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cisco Talos analysis indicates an ongoing, low-noise malware campaign named OfflRouter active in Ukraine since 2015 that uses VBA macro-infected .DOC files (and/or a standalone ctrlpanel.exe) to drop a .NET executable which infects .DOC files, copies/executes plugin files on removable media (.ORP), and achieves persistence via Windows Registry modifications; propagation is primarily via manual sharing and removable media rather than automated email, limiting scale but resulting in confidential documents being uploaded to public repositories and continued detections on VirusTotal since 2018.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.