Skip to main content
Mallory
MalwareUsed by 3 actors

WinDealer

WinDealer is a Windows backdoor/RAT malware family associated with the China-linked threat actor LuoYu, also referred to in the provided content as SinisterEye LuoYu. It is described as a primary Windows implant and has been used alongside SpyDealer on Android. Reported delivery tradecraft includes adversary-in-the-middle or ISP/backbone-level interception of Windows software update traffic, specifically manipulation of Windows update mechanisms on ChinaNet AS4134 to deliver WinDealer to targets, including foreign entities operating inside China. The malware is referenced as part of LuoYu operations and is also mentioned in connection with Chinese-origin activity involving WinDealer and ReverseWindow. The content further notes WinDealer RAT among malware families discussed in threat reporting. High-confidence context from the provided material ties WinDealer to espionage-focused operations, Windows targeting, and network-infrastructure-assisted malware delivery rather than conventional user-driven infection vectors.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
LuoYu

In a research paper presented by TeamT5, XDealer was shown to be associated with Luoyu, a threat actor with Chinese origins that used the WinDealer and ReverseWindow malware families.

via trend micro researchtrendmicro.com
SinisterEye

Target Technologies: Windows operating system update mechanisms, specifically Windows software update traffic intercepted and manipulated via adversary-in-the-middle to deliver WinDealer... Malware and Tools: WinDealer (Windows backdoor primary implant), SpyDealer (Android surveillance malware), custom passive MOTS injection framework operating at network infrastructure level.

via cyfirma othercyfirma.com
Cascade Panda

...SinisterEye... to deliver malware like WinDealer (for Windows) and SpyDealer (for Android)...

via the hacker newsthehackernews.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1195Supply Chain CompromiseEvidence1

Initial Access: Supply chain compromise through overseas telecommunications provider, exploiting a trusted third-party network connection to bypass perimeter defenses.

T1557Adversary-in-the-MiddleEvidence1

Initial Access: Adversary-in-the-middle attacks confirmed capability to intercept network traffic at ISP-level or backbone-level within AS4134 (ChinaNet). Legitimate software update requests from victim machines are intercepted in transit, with server responses replaced by a malicious payload before reaching the victim.

Discovery

1 technique
T1018Remote System DiscoveryEvidence1
TacticDiscovery

Active Directory reconnaissance post-compromise.

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence1

Initial Access: Adversary-in-the-middle attacks confirmed capability to intercept network traffic at ISP-level or backbone-level within AS4134 (ChinaNet). Legitimate software update requests from victim machines are intercepted in transit, with server responses replaced by a malicious payload before reaching the victim.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.