Cybersecurity researchers have identified a new malware family named YiBackdoor, which exhibits significant code similarities with the IcedID and Latrodectus malware strains. YiBackdoor is capable of executing arbitrary commands, collecting system information, capturing screenshots, and deploying plugins to expand its functionality. The malware employs anti-analysis techniques, injects itself into the svchost.exe process, and achieves persistence via the Windows Run registry key. Initial analysis suggests that YiBackdoor may be developed by the same actors behind IcedID and Latrodectus and could be used in conjunction with these loaders to facilitate initial access for ransomware attacks. Limited deployments indicate that YiBackdoor is either under development or in a testing phase.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-on reporting noted that researchers were also analyzing novel YiBackdoor samples in the context of newly emerging ZLoader versions. This represented an additional technical development in the broader malware ecosystem discussion.
Analysis found major code similarities between YiBackdoor and the IcedID and Latrodectus malware families, suggesting a development or operational relationship. Multiple outlets reported this linkage as a key technical finding.
Security researchers reported a newly identified malware family named YiBackdoor. The reporting emerged in late September 2025 and described it as a distinct backdoor under active analysis.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.