Skip to content

Malware

CrimsonIAS

According to ThreatConnect, CrimsonIAS is a Delphi-written backdoor dating back to at least 2017.

CrimsonIAS is a Windows malware family operated by Mustang Panda.

Background

ThreatConnect describes CrimsonIAS as a backdoor written in Delphi with roots going back at least to 2017. It lets operators execute command line tools, exfiltrate files, and push files onto the compromised host. What sets CrimsonIAS apart is that it only listens for inbound connections, distinguishing it from the typical Windows backdoor that beacons outward.


Source: Malpedia (Fraunhofer FKIE).