We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Win32/Ryknos
Detected by Microsoft Defender Antivirus
Aliases: No associated aliases
Summary
Windows Defender Antivirus detects and removes this threat.
Win32/Ryknos is a family of backdoor Trojans that targets computers running certain versions of Microsoft Windows. The trojan opens a backdoor on the infected computer to receive commands from attackers. If the rootkit WinNT/F4IRootkit is already installed on the target computer, the Trojan uses the rootkit to hide.