We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Backdoor:Win64/Spiderpig.ZX
Aliases: No associated aliases
Summary
Backdoor:Win64/Spiderpig.ZX is a detection for a backdoor trojan used by the threat actor Microsoft tracks as Canary Typhoon, a nation-state threat actor based out of China.
The malware gathers information from the system that is sent to the threat actor-controlled command and control (C2) server, launches commands and performs downloads, uploads, and launches additional payloads.
As the malware is associated with advanced persistent threat (APT) attacks, remove the infected system from the network and perform a thorough investigation of the network for other compromised devices.