VOOZH about

URL: https://attack.mitre.org/software/S0636/

⇱ VaporRage, Software S0636 | MITRE ATT&CK®


ATT&CKcon 7.0 is coming October 27-28, 2026. Learn more about ATT&CKcon 7.0 and submit your proposal.
  1. Home
  2. Software
  3. VaporRage

VaporRage

VaporRage is a shellcode downloader that has been used by APT29 since at least 2021.[1]

ID: S0636
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 04 August 2021
Last Modified: 25 April 2025
Enterprise Layer
download view 👁 Image

Techniques Used

Domain ID Name Use
Enterprise T1071 .001 Application Layer Protocol: Web Protocols

VaporRage can use HTTP to download shellcode from compromised websites.[1]

Enterprise T1140 Deobfuscate/Decode Files or Information

VaporRage can deobfuscate XOR-encoded shellcode prior to execution.[1]

Enterprise T1480 Execution Guardrails

VaporRage has the ability to check for the presence of a specific DLL and terminate if it is not found.[1]

Enterprise T1105 Ingress Tool Transfer

VaporRage has the ability to download malicious shellcode to compromised systems.[1]

Groups That Use This Software

ID Name References
G0016 APT29

[1]

References

×