ReverseWindow is a Windows malware family associated with the PRC-linked espionage actor LuoYu. It has been observed in overlap with infrastructure identified as ShadowPad command-and-control, indicating operational ties within the broader Chinese cyber-espionage ecosystem. Public reporting places ReverseWindow alongside other long-lived espionage malware used by China-linked operators, and it has been referenced together with WinDealer in activity attributed to LuoYu. High-confidence public facts in this context establish ReverseWindow as malware used in targeted espionage operations and show it communicating with command-and-control infrastructure over a custom TCP service. No more specific, well-corroborated functional classification or delivery mechanism is directly established here beyond its role as an espionage backdoor-like implant communicating with remote control infrastructure on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spyder and ReverseWindow are APT malware utilized by PRC-linked cyber espionage threat actors (respectively APT41 and LuoYu).
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family associated with Luoyu, mentioned in attribution context as related to XDealer.
APT malware identified on VirusTotal as communicating with a ShadowPad C2 IP, indicating shared or overlapping C2 infrastructure.
APT malware observed communicating with a ShadowPad C2 IP, indicating infrastructure overlap or shared C2 usage.
A malware family listed as communicating with an IP identified as ShadowPad C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.