{
  "family": "potao",
  "sample_count": 1,
  "category": "trojan",
  "description": "<h3>Executive Summary</h3>\nPotao (also known as Potao Express) is a highly targeted espionage Trojan and Custom Backdoor frequently attributed to nation-state level Advanced Persistent Threat (APT) groups. Unlike financially motivated crimeware, Potao is utilized almost exclusively for targeted data theft, strategic intelligence gathering, and long-term espionage, often targeting government entities, military organizations, and high-value journalism targets in Eastern Europe.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nPotao relies heavily on highly targeted spear-phishing campaigns. It famously utilizes \"TrueCrypt\" themed lures or malicious Word documents exploiting known vulnerabilities (e.g., CVE-2012-0158) to gain initial execution. It has also been delivered via compromised legitimate software update mechanisms (supply chain attacks).\n\nIts technical capabilities are focused entirely on stealth and deep exfiltration:\n<ul>\n<li><strong>Modular Espionage Framework:</strong> Potao acts as a central hub. Once installed, it downloads specific espionage plugins based on the victim's profile. These plugins include advanced keyloggers, screen scrapers, and tools designed to steal highly specific file types (like PGP rings or TrueCrypt volumes).</li>\n<li><strong>Air-Gap Bridging (USB Propagation):</strong> Potao features a specialized module designed to infect and monitor USB drives. This allows the malware to \"jump\" air-gapped networks, collecting data from isolated machines and exfiltrating it when the USB drive is plugged back into an internet-connected host.</li>\n<li><strong>SMS and Communications Theft:</strong> Certain variants of the Potao campaign have also targeted mobile devices (Android) or intercepted SMS messages, specifically to bypass Two-Factor Authentication (2FA) mechanisms for targeted accounts.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nA Potao detection is a critical national security or enterprise crisis. It indicates that the organization is the specific target of a highly sophisticated, well-funded espionage operation. The primary threat is the catastrophic loss of state secrets, intellectual property, and deeply confidential communications.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Covert Incident Response:</strong> Do not immediately tip your hand. Engage a specialized Incident Response (IR) firm. Aggressive, immediate remediation (like instantly wiping a single machine) will cause the APT group to \"go dark,\" alter their C2 infrastructure, and burrow deeper into the network.</li>\n<li><strong>Air-Gap Audits:</strong> If Potao is detected, assume all USB devices within the organization are potentially compromised and acting as data carriers.</li>\n<li><strong>Coordinated Network-Wide Eradication:</strong> Eradication requires a highly orchestrated, simultaneous event to sever all C2 connections, wipe all infected endpoints, and rotate every credential globally at the exact same time.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "APT.Potao",
    "Trojan.Potao",
    "Backdoor.Win32.Potao",
    "Potao Express"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1092",
    "T1071",
    "T1566.001",
    "T1114"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-02T07:41:56Z",
  "type": "Trojan / APT Espionage Tool",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}