Samurai
S1099 · Windows
Samurai is a passive backdoor that has been used by ToddyCat since at least 2020. Samurai allows arbitrary C# code execution and is used with multiple modules for remote administration and lateral movement.
ATT&CK S1099
1 actors documented
Sigma rules0
YARA rules0
Live IOCs0