Retadup is a multifunctional Windows worm and worming backdoor active since at least 2015, with especially heavy impact in Latin America. It is designed to establish persistence, propagate to additional systems and removable media, profile infected hosts, and retrieve or install follow-on payloads. Multiple variants have been documented, including implementations built around AutoIt or AutoHotkey interpreters paired with malicious scripts. Retadup commonly spreads by planting malicious shortcut files on connected drives and shared locations, using social engineering themes that mimic software or system updates to induce execution. Persistence has been achieved through autorun mechanisms and scheduled tasks, while anti-analysis logic checks for security products, sandboxes, virtual machines, and analysis tooling and may terminate or self-delete when such environments are detected.
Retadup supports classic backdoor functionality, including command execution, file download and update operations, process management, and communication with command-and-control infrastructure over obfuscated HTTP requests. Documented surveillance and theft capabilities include host profiling, browser password extraction, keylogging, and screenshot capture. It has also been associated with broader monetization and post-compromise activity: the most common secondary payload observed was a cryptocurrency miner, and campaigns have also delivered Stop ransomware, the Arkei password stealer, and the related HoudRat remote access tool. Some reporting additionally attributes DDoS and espionage-oriented information gathering capabilities to the malware family. Retadup’s propagation model, modular payload delivery, and long-running botnet operations made it a significant regional threat until a law-enforcement-assisted infrastructure takeover exploited a design flaw in its command-and-control protocol to disinfect large numbers of infected systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Retadup achieves persistence by either creating a registry value in HKCU\Software\Microsoft\Windows\CurrentVersion\Run and/or creating a scheduled task. The scheduled task is created using the schtasks.exe utility and is set to execute every minute.
Retadup achieves persistence by either creating a registry value in HKCU\Software\Microsoft\Windows\CurrentVersion\Run and/or creating a scheduled task. The scheduled task is created using the schtasks.exe utility and is set to execute every minute.
Retadup achieves persistence by either creating a registry value in HKCU\Software\Microsoft\Windows\CurrentVersion\Run and/or creating a scheduled task.
Retadup achieves persistence by either creating a registry value in HKCU\Software\Microsoft\Windows\CurrentVersion\Run and/or creating a scheduled task. The scheduled task is created using the schtasks.exe utility and is set to execute every minute.
Retadup achieves persistence by either creating a registry value in HKCU\Software\Microsoft\Windows\CurrentVersion\Run and/or creating a scheduled task.
Retadup achieves persistence by either creating a registry value in HKCU\Software\Microsoft\Windows\CurrentVersion\Run and/or creating a scheduled task.
Since the core is distributed either in the form of AutoHotkey source code or AutoIt bytecode... the authors tried to obfuscate it to make analysis harder.
Updateself: causes the script to polymorphically mutate itself (it prepends a single random comment line and renames some of its obfuscated variable names)
The dropped LNK files essentially mimic users’ already existing files and they seem to be successful at convincing many of them that they are just benign shortcuts.
we’ve also observed the AutoIt script directly downloading a PE file, deleting its zone identifier and running it directly from disk.
There are many anti-analysis checks and their specific implementation differs in various Retadup variants.
Then it makes some basic checks to see if it is being analyzed. If it detects that it is under analysis, it also exits silently... some variants also check if processes with names such as vmtoolsd.exe or procmon.exe are running, if directories with names such as C:\CWSandbox\ or C:\cuckoo\ exist and if modules with names such as SbieDll.dll or api_log.dll are loaded in the current process.
Most samples also implement a way to delay their execution. At the start of their execution, they either perform a single long sleep or a series of many short sleeps.
Embedded in the AutoIt script was a shellcode capable of loading an embedded PE file. The shellcode was copied into executable memory allocated through VirtualAlloc. The AutoIt function DllCallAddress was then used to transfer control to the shellcode which in turn loaded and passed control to the final PE payload.
RETADUP’s backdoor routines include: Starting, terminating, and restarting processes
It gathers system information. The malware executes a command to retrieve system information via C:\WINDOWS\system32\cmd.exe /c SystemInfo... the malware contains the following strings, which may indicate that it attempts to gather system information of affected machines: @ComputerName @UserName @LogonDomain DriveGetSerial("C:") @IPAddress1 EnvGet("OS") @OSLang @OSVersion @OSBuild
There are many anti-analysis checks and their specific implementation differs in various Retadup variants.
Then it makes some basic checks to see if it is being analyzed. If it detects that it is under analysis, it also exits silently... some variants also check if processes with names such as vmtoolsd.exe or procmon.exe are running, if directories with names such as C:\CWSandbox\ or C:\cuckoo\ exist and if modules with names such as SbieDll.dll or api_log.dll are loaded in the current process.
We have observed its attempts to gain footholds in the systems and the local networks’ shared folders.
Created in 2015 and primarily infected computers throughout Latin America, RETADUP is a multi-functional Windows malware that is capable of mining cryptocurrency using the computing power of infected machines
28 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-functional Windows malware and botnet used for cryptocurrency mining, DDoS activity, espionage, persistence, self-propagation, and delivery of additional payloads.
Windows worm written in AutoIt/AutoHotkey that establishes persistence, spreads via malicious LNK files on connected drives, communicates with C2 over HTTP, and installs additional payloads including cryptocurrency miners and other malware.
Information-stealing worm whose C&C infrastructure hosted GhostCtrl and which was part of the broader attack discussed in the article.
A worm-propagating backdoor and information stealer delivered via malicious LNK files and abused AutoIt execution. It masquerades as Windows/browser updaters, spreads by copying itself and shortcut files across drives and shared/removable folders, steals browser passwords, logs keystrokes, takes screenshots, executes commands, communicates with C2, and includes anti-analysis/self-destruct checks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.