Last seven days
- First activity
- Sep 11, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 0 hostnames
Rozena is a Windows backdoor malware family known for using staged PowerShell execution and fileless techniques to establish remote access on compromised hosts.
Profile source: Mallory opens in a new tabRozena
Rozena is a Windows backdoor malware family known for using staged PowerShell execution and fileless techniques to establish remote access on compromised hosts. First observed in 2015 and later seen in updated variants, Rozena commonly masquerades as a Microsoft Word document or other benign software while remaining a Windows executable. Its execution chain has included obfuscated and Base64-encoded PowerShell, in-memory decryption, and shellcode injection into PowerShell.exe using Windows API functions such as VirtualAlloc and CreateThread. Reported shellcode behavior includes opening a reverse shell or Meterpreter-style remote session that enables attacker command execution and file transfer.
Rozena has been delivered through multiple infection vectors. Documented campaigns used phishing lures and weaponized Microsoft Office documents exploiting CVE-2022-30190 (Follina) to invoke MSDT and launch PowerShell-based downloaders. Other observed packaging included MSI installers masquerading as legitimate software and samples dropped by other malware or downloaded from malicious sites. In Follina-based chains, Rozena was retrieved after remote HTML content triggered msdt.exe, followed by additional scripting to download the payload, establish persistence, and present a decoy document to distract the victim.
The malware is notable for defense evasion through abuse of legitimate Windows tooling, obfuscated PowerShell syntax, hidden execution, encoded commands, and fileless staging. Some observed installers also added Microsoft Defender exclusions before launching the payload. Persistence has been observed via Windows Run keys, and Rozena variants have used temporary or staged files that are decrypted in memory and then removed. The malware has been associated with reverse-shell functionality rather than ransomware behavior itself, although it has appeared in broader intrusion chains where other malware families or later-stage payloads were also discussed. Rozena targets Windows systems and is primarily characterized as a backdoor providing attacker-controlled remote access and post-compromise execution.
C2 tracking
Derp observations, rolling seven-day window
Samples
3ebb5316c670fdc6b56a237603d78468d39abdca51acdb4387b5e3562d61d863 4bc4987862318f1e1772155e85b0e32c1c9cb90afeefb4d04f3b58d1b51473d6 4eff95566912a2032bc6aff7f0a830ca29f18d815068cfe4bd6240d0fb7b117e b87c5c316e18095207279dfa929f5f7da5430072902792d54d00158e05616dcd e722b1b022ddce866f855bac30ea437e6f29eddccdceaa51f61ee5e66767beb3 Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.