Skip to content

Malware

PeddleCheap

PeddleCheap is a module of the DanderSpritz framework which surface with the "Lost in Translation" release of TheShadowBrokers leaks.

PeddleCheap is a Windows malware family operated by Equation Group.

Background

PeddleCheap is a component of the DanderSpritz framework that became public through TheShadowBrokers' "Lost in Translation" leak. In May 2020, ESET noted the discovery of unusual PeddleCheap samples wrapped in a custom packer that, up to that point, had been linked solely to Winnti.


Source: Malpedia (Fraunhofer FKIE).