Skip to content

Malware

Saitama Backdoor

aka AMATIAS · Saitama

This in .Net witten backdoor abuses the DNS protocoll for its C2 communication.

Saitama Backdoor, also known as AMATIAS, Saitama, is a Windows malware family operated by OilRig.

Background

Written in .NET, this backdoor tunnels its C2 traffic through the DNS protocol. It also leans on additional tricks such as lengthy randomized sleeps and compression to stay under the radar.


Source: Malpedia (Fraunhofer FKIE).