DSDownloader is a malware family referenced in phishing-driven intrusion campaigns attributed to the Silent Werewolf threat actor. The provided reporting places it alongside XDSpy, XDigo, and UTask in attacks targeting organizations in Russia, Belarus, Ukraine, Moldova, and Serbia, including sectors such as nuclear, aircraft, instrumentation, and mechanical engineering, as well as Moldovan and Russian companies. Based on the cited context, DSDownloader is used in phishing campaigns and is described as capable of downloading additional payloads and stealing sensitive information from compromised hosts. The content does not provide further verified technical details on its implementation, persistence, command-and-control, or specific indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader-type malware family referenced as used in campaigns targeting Russia and Moldova; described as capable of downloading additional payloads and stealing sensitive information.
Downloader malware used by Silent Werewolf to fetch and install additional payloads on victim systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.