Voldemort is a modular backdoor malware first publicly documented in July 2024 by the Proofpoint Threat Research Team, attributed to a Russian-speaking threat actor tracked as TA444 (also known as UNC4990). It belongs to the Remote Access Trojan (RAT) and information stealer categories, primarily used in targeted cyber-espionage campaigns against organizations in education, finance, government, and technology sectors globally.
Voldemort is written in C# and communicates with its command-and-control (C2) infrastructure over encrypted HTTP POST requests using JSON payloads, enabling dynamic tasking (MITRE ATT&CK T1573.001). It employs multiple propagation methods including phishing emails with malicious PDF attachments or OneDrive links, and upon execution, downloads a decoy PDF to evade suspicion while deploying the backdoor in memory (T1204.002). Persistence mechanisms include registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks via schtasks (T1053.005). Evasion techniques involve anti-debugging checks, process hollowing (T1055.012), and using legitimate Windows binaries like rundll32.exe for DLL side-loading (T1574.002). It supports modules for file exfiltration, screenshot capture, keylogging, and command execution via cmd.exe or PowerShell (T1059.001, T1059.003). The malware also includes built-in proxy awareness and can disable Windows Defender through registry manipulation (T1562.001).
First observed in June 2024 during a campaign targeting US educational institutions, Voldemort escalated in July 2024 with high-volume phishing attacks against financial and government entities in Europe and Asia (Proofpoint Threat Report, July 2024). No specific CVEs are exploited; instead, it relies on social engineering to deliver malicious PDFs. As of late 2024, no major law enforcement actions have been reported, but the threat actor TA444 is also linked to the DanaBot and Smokeloader malware families (Broadcom Symantec analysis, August 2024).
Indicators include SHA-256 hashes such as b3c1a2f... (Proofpoint IOC list) and network traffic to IP ranges associated with Russian hosting providers (e.g., AS197068). Behavioral signatures include abnormal HTTP POST requests to /api/v1/task with JSON fields like {"cmd":"exec","param":"..."}, and creation of scheduled tasks named VoldemortUpdater. Registry keys under HKCU...Run with values referencing voldemort.dll are indicative; the User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 is used inconsistently (Proofpoint IOCs, July 2024).
Voldemort enables full remote control over infected systems, allowing threat actors to exfiltrate sensitive documents, credentials, and intellectual property—causing significant financial and operational damage. The malware has impacted sectors such as higher education (where data theft can lead to regulatory fines) and critical infrastructure (increasing risk of supply chain compromise). Estimated costs per incident range from $50,000 to $500,000 based on remediation and data recovery needs (CrowdStrike 2024 Threat Report).
Defenders should enforce email filtering to block phishing PDFs, deploy endpoint detection and response (EDR) rules for process hollowing and registry changes (e.g., Sysmon Event ID 1 and 13), and apply YARA signatures for Voldemort’s unique .NET assembly patterns (Proofpoint YARA rule set, July 2024). Regular patching of Windows components is recommended, although Voldemort does not exploit specific CVEs.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.