---
title: Voldemort
description: An espionage campaign delivering the Voldemort backdoor was recently observed targeting over 70 organizations.
---

[Insights, news, education and announcements from PolySwarm](https://blog.polyswarm.io)

# [Voldemort](https://blog.polyswarm.io/voldemort)

 Written by [The Hivemind](https://blog.polyswarm.io/author/the-hivemind) | Sep 9, 2024 4:52:20 PM

**Verticals Targeted:** Insurance, Aerospace, Transportation, Education, Finance, Technology, Healthcare, Automotive, Hospitality, Energy, Government, Media, Manufacturing, Telecommunications 

## **Executive Summary**

## An espionage campaign delivering the Voldemort backdoor was recently observed targeting over 70 organizations. The campaign uses a novel attack chain to deliver the malware, leveraging Google Sheets for command and control (C2).

**Key Takeaways**

- An espionage campaign delivering the Voldemort backdoor was recently observed targeting over 70 organizations. 
- The campaign uses a novel attack chain to deliver the malware, leveraging Google Sheets for command and control (C2).
- Voldemort is a custom backdoor written in C.

**What is Voldemort?**

### An espionage campaign delivering the Voldemort backdoor was recently observed targeting over 70 organizations. The campaign uses a novel attack chain to deliver the malware, leveraging Google Sheets for command and control (C2). Proofpoint discovered the campaign last month and recently [reported](https://www.proofpoint.com/us/blog/threat-insight/malware-must-not-be-named-suspected-espionage-campaign-delivers-voldemort) on this activity.

Voldemort is a custom backdoor written in C. It is capable of collecting system information, uploading files, and executing commands received from the C2. Voldemort’s attack chain leverages Google Sheets for C2, a method not commonly used. 

A Voldemort infection begins with phishing emails using a tax-themed lure. The emails contain malicious links that send the victim to an actor-controlled landing page or directly to a malicious file. When the victim chooses “View Document,” a check is performed on the browser’s User Agent to determine if it is a Windows system. If a Windows system is detected, the victim is redirected to a URI that prompts Windows Explorer to display either an LNK file or ZIP file masquerading as a PDF. Executing the LNK file triggers the rest of the attack chain, resulting in deployment of Voldemort on the victim’s machine. 

The Voldemort campaign has spread worldwide, with over 20,000 phishing emails sent. At the campaign’s peak, 6000 emails were sent in one day. Targeted entities include those in the insurance, aerospace, transportation, education, finance, technology, healthcare, automotive, hospitality, energy, government, media, manufacturing, and telecommunications verticals. Most of the targets were located in the US, Europe, and Asia. At this time, the threat actor behind the campaign remains a mystery. 

**IOCs**

PolySwarm has multiple samples associated with this activity.

 

[0b3235db7e8154dd1b23c3bed96b6126d73d24769af634825d400d3d4fe8ddb9](https://polyswarm.network/scan/results/file/0b3235db7e8154dd1b23c3bed96b6126d73d24769af634825d400d3d4fe8ddb9)

[fa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f](https://polyswarm.network/scan/results/file/fa383eac2bf9ad3ef889e6118a28aa57a8a8e6b5224ecdf78dcffc5225ee4e1f)

 

You can use the following CLI command to search for all Voldemort samples in our portal:

**$ polyswarm link list -f Voldemort**

 

***Don’t have a PolySwarm account? Go* [here](https://polyswarm.network/) *to sign up for a free Community plan or subscribe.***

***Contact us at* [hivemind@polyswarm.io](mailto:hivemind@polyswarm.io) *| Check out our* [blog](https://blog.polyswarm.io/) ***|* **[Subscribe](https://polyswarm.io/ransomwarereport/) *to our reports.***

 

[View full post](https://blog.polyswarm.io/voldemort)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "The Hivemind"
  },
  "dateModified" : "2024-09-09T17:15:59.768Z",
  "datePublished" : "2024-09-09T16:52:20Z",
  "headline" : "Voldemort",
  "image" : {
    "@type" : "ImageObject",
    "height" : 900,
    "url" : "https://5737925.fs1.hubspotusercontent-na1.net/hubfs/5737925/Threat%20Bulletin%20Images/VOLDEMORT.jpg",
    "width" : 1600
  },
  "mainEntityOfPage" : "https://blog.polyswarm.io/voldemort",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/5737925/Social%20Icons_PS-1.png",
      "width" : 59.820896
    },
    "name" : "The PolySwarm Blog"
  }
}
```