Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 16:59:17 UTC Home > List all groups > List all tools > List all groups using tool VIDEOKILLER Tool: VIDEOKILLER Names VIDEOKILLER Category Malware Type Backdoor Description (FireEye) VIDEOKILLER is a .NET backdoor similar to RADIOSTAR that handles commands from the C&C server. It masquerades as conhost.exe. The majority of strings it contains are Base64 encoded, though some are not, such as the string “It’s Ok” which is potentially used for logging throughout execution. Information Last change to this tool card: 15 May 2021 Download this tool card in JSON format All groups using tool VIDEOKILLER Changed Name Country Observed APT groups   Operation Ghostwriter 2017-Jan 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=989eb461-9f94-496a-a0c1-9218ab31462f https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=989eb461-9f94-496a-a0c1-9218ab31462f Page 1 of 1