Voldemort is a custom Windows backdoor written in C and used in China-aligned cyberespionage operations. It was publicly associated with TA415, also tracked as APT41 and Brass Typhoon, in campaigns beginning in August 2024. Later campaigns targeting Taiwan’s semiconductor ecosystem used Voldemort under the UNK_FistBump cluster; this cluster is tracked separately from TA415 despite tooling overlap.
Voldemort provides host-information collection, file and directory operations, remote command execution, and the ability to load or deliver follow-on payloads. It uses Google Sheets through the Google Sheets API for command-and-control and Google Drive for associated storage and data-transfer functions. Observed variants employ dynamic API resolution, encrypted configuration and strings, and delayed beaconing with jitter. Some later variants protected collected host data with Base64 encoding and RC4 encryption.
Observed delivery chains have relied on spearphishing lures, including tax-authority impersonation and employment-themed messages. These chains have used malicious shortcut files masquerading as documents, remote WebDAV-hosted content, Python-based staging, and DLL sideloading through legitimate software components to load the Voldemort DLL. Targeting has included government, aerospace, insurance, chemicals, manufacturing, transportation, academic, and semiconductor-sector organizations across multiple regions, with activity assessed as intelligence collection rather than financially motivated crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since August 2024, APT41 has been observed using free web hosting services to distribute malware families including VOLDEMORT, DUSTTRAP, and TOUGHPROGRESS.
Proofpoint researchers identified an unusual campaign delivering malware that the threat actor named “Voldemort”. ... Voldemort is a custom backdoor written in C. It has capabilities for information gathering and to drop additional payloads.
...shifted to delivery of the custom Voldemort backdoor in late May 2025... executes ... CiscoCollabHost.exe ... loads ... CiscoSparkLauncher.dll... delivery of the custom Voldemort backdoor, which uses Google Sheets for command and control (C2).
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Chinese state-aligned hackers have ramped up espionage efforts against Taiwan's semiconductor ecosystem through spear-phishing campaigns... UNK_FistBump used job-themed lures, posing as graduate students applying for positions. The attackers sent phishing emails from compromised Taiwanese university email accounts to HR and recruiting teams at semiconductor companies. Attached documents led to malware-laced ZIP or PDF files hosted on file-sharing platforms such as Zendesk and Filemail.
The commands the malware supports are as follows: Ping Dir Download Upload Exec Copy Move Sleep Exit
If the LNK is executed, it will invoke PowerShell to run Python.exe from a third WebDAV share on the same tunnel (\library\), passing a Python script on a fourth share (\resource\) on the same host as an argument.
“...runs a VBS script Store.vbs…” / “Execution… runs another VBS file also called Store.vbs…”
This causes Python to run the script without downloading any files to the computer, with dependencies being loaded directly from the WebDAV share.
To decrypt strings, the malware relies on an algorithm that looks very similar to XTEA... With API calls resolved, the malware continues by decrypting its own configuration... decrypted via an XOR cipher using the executable name “CiscoCollabHost.exe”.
The malware then has a routine to dynamically invoke APIs that is relatively unique. To resolve functions and call them, the malware passes a DLL handle, a callback to a function, and the arguments to the function it’s trying to call.
It also uses a PDF icon to masquerade as a different file type. These two techniques may lead the recipient to believe it is a local PDF file, which may increase the likelihood of clicking on the content.
“...decrypts the RC4-encrypted Cobalt Strike Beacon payload from the rc4.log file using the key qwxsfvdtv…” / “...Base64-encoded and RC4-encrypted… using… CiscoCollabHost.exe as the RC4 key…” / “...payload which is XOR encoded with the key mysecretkey.”
The malware used DLL sideloading techniques and, in some cases, Google Sheets as a command-and-control channel... The malware communicated with C2 servers over TCP port 465 using FakeTLS and XOR encryption.
Rather than using dedicated infrastructure or even compromised infrastructure, the malware utilizes Google Sheets infrastructure for C2, data exfiltration and executing commands from the operators.
The malware used DLL sideloading techniques and, in some cases, Google Sheets as a command-and-control channel.
The exploited site delivered a malware payload, which we have dubbed “TOUGHPROGRESS”, that took advantage of Google Calendar for command and control (C2). Misuse of cloud services for C2 is a technique that many threat actors leverage in order to blend in with legitimate activity.
This will result in displaying a Windows shortcut file... hosted on the same TryCloudflare host, but in another WebDAV share, \pub\. ... If the LNK is executed, it will invoke PowerShell to run Python.exe from a third WebDAV share on the same tunnel (\library\), passing a Python script on a fourth share (\resource\). | Voldemort is a backdoor with capabilities for information gathering and can load additional payloads. Proofpoint observed Cobalt Strike hosted on the actor's infrastructure, and it is likely that is one of the payloads that would be delivered.
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actors abusing WebDAV is a common tactic, seen in past attacks delivering Bumblebee and Voldemort malware.
Backdoor referenced as previously seen in Chinese-nexus campaigns (mentioned as historical context).
Backdoor referenced as previously delivered in China-aligned campaigns (no additional functional details provided in the content).
Custom backdoor previously delivered by TA415 in phishing campaigns before the group shifted to using VS Code Remote Tunnels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.