Voldemort is a custom Windows backdoor written in C and associated primarily with China-aligned espionage activity. It has been linked to TA415, which overlaps with APT41 and Brass Typhoon, and has also been observed in separate China-aligned intrusion clusters such as UNK_FistBump targeting Taiwan’s semiconductor ecosystem. The malware has been used in campaigns against government, aerospace, chemicals, insurance, manufacturing, transportation, university, and semiconductor-related organizations, with activity indicating intelligence collection rather than financially motivated crime.
Voldemort has been delivered through targeted phishing campaigns using lure themes tailored to victims, including tax and employment themes. Observed delivery chains have used landing pages, remote WebDAV-hosted content, malicious shortcut files, Python-based staging, and DLL sideloading through legitimate executables. In multiple campaigns, a legitimate Cisco WebEx-related binary was abused to sideload the Voldemort payload.
The backdoor supports host reconnaissance, file and directory operations, command execution, configurable sleep behavior, and delivery or loading of additional payloads. Reported command support includes functions equivalent to pinging the controller, listing directories, downloading and uploading files, copying and moving files, executing commands, changing sleep intervals, and terminating execution. It has also been assessed as capable of facilitating follow-on payload deployment, including Cobalt Strike.
A notable characteristic of Voldemort is its abuse of legitimate cloud services for command and control and related storage functions. It has used Google Sheets as a command channel and Google Drive for associated storage and exfiltration-related operations, authenticating with embedded Google API credentials. The malware also employs anti-analysis and evasion features including dynamic API resolution, encrypted or obfuscated configuration handling, and jittered sleep intervals.
Voldemort has figured in broader Chinese cyber-espionage tradecraft that favors trusted web services and living-off-the-land style staging to reduce detection. Its reuse across multiple China-aligned clusters suggests either capability sharing or common sourcing within that ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Proofpoint researchers identified an unusual campaign delivering malware that the threat actor named “Voldemort”. ... Voldemort is a custom backdoor written in C. It has capabilities for information gathering and to drop additional payloads.
Proofpoint researchers identified an unusual campaign delivering malware that the threat actor named “Voldemort”. ... Voldemort is a custom backdoor written in C. It has capabilities for information gathering and to drop additional payloads.
...shifted to delivery of the custom Voldemort backdoor in late May 2025... executes ... CiscoCollabHost.exe ... loads ... CiscoSparkLauncher.dll... delivery of the custom Voldemort backdoor, which uses Google Sheets for command and control (C2).
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Chinese state-aligned hackers have ramped up espionage efforts against Taiwan's semiconductor ecosystem through spear-phishing campaigns... UNK_FistBump used job-themed lures, posing as graduate students applying for positions. The attackers sent phishing emails from compromised Taiwanese university email accounts to HR and recruiting teams at semiconductor companies. Attached documents led to malware-laced ZIP or PDF files hosted on file-sharing platforms such as Zendesk and Filemail.
The commands the malware supports are as follows: Ping Dir Download Upload Exec Copy Move Sleep Exit
If the LNK is executed, it will invoke PowerShell to run Python.exe from a third WebDAV share on the same tunnel (\library\), passing a Python script on a fourth share (\resource\) on the same host as an argument.
“...runs a VBS script Store.vbs…” / “Execution… runs another VBS file also called Store.vbs…”
This causes Python to run the script without downloading any files to the computer, with dependencies being loaded directly from the WebDAV share.
To decrypt strings, the malware relies on an algorithm that looks very similar to XTEA... With API calls resolved, the malware continues by decrypting its own configuration... decrypted via an XOR cipher using the executable name “CiscoCollabHost.exe”.
The malware then has a routine to dynamically invoke APIs that is relatively unique. To resolve functions and call them, the malware passes a DLL handle, a callback to a function, and the arguments to the function it’s trying to call.
It also uses a PDF icon to masquerade as a different file type. These two techniques may lead the recipient to believe it is a local PDF file, which may increase the likelihood of clicking on the content.
“...decrypts the RC4-encrypted Cobalt Strike Beacon payload from the rc4.log file using the key qwxsfvdtv…” / “...Base64-encoded and RC4-encrypted… using… CiscoCollabHost.exe as the RC4 key…” / “...payload which is XOR encoded with the key mysecretkey.”
The malware used DLL sideloading techniques and, in some cases, Google Sheets as a command-and-control channel... The malware communicated with C2 servers over TCP port 465 using FakeTLS and XOR encryption.
Rather than using dedicated infrastructure or even compromised infrastructure, the malware utilizes Google Sheets infrastructure for C2, data exfiltration and executing commands from the operators.
The malware used DLL sideloading techniques and, in some cases, Google Sheets as a command-and-control channel.
The exploited site delivered a malware payload, which we have dubbed “TOUGHPROGRESS”, that took advantage of Google Calendar for command and control (C2). Misuse of cloud services for C2 is a technique that many threat actors leverage in order to blend in with legitimate activity.
This will result in displaying a Windows shortcut file... hosted on the same TryCloudflare host, but in another WebDAV share, \pub\. ... If the LNK is executed, it will invoke PowerShell to run Python.exe from a third WebDAV share on the same tunnel (\library\), passing a Python script on a fourth share (\resource\). | Voldemort is a backdoor with capabilities for information gathering and can load additional payloads. Proofpoint observed Cobalt Strike hosted on the actor's infrastructure, and it is likely that is one of the payloads that would be delivered.
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actors abusing WebDAV is a common tactic, seen in past attacks delivering Bumblebee and Voldemort malware.
Backdoor referenced as previously seen in Chinese-nexus campaigns (mentioned as historical context).
Backdoor referenced as previously delivered in China-aligned campaigns (no additional functional details provided in the content).
Custom backdoor previously delivered by TA415 in phishing campaigns before the group shifted to using VS Code Remote Tunnels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.