DownPaper (Malware Family) By Fraunhofer FKIE Archived: 2026-04-05 21:07:49 UTC win.downpaper (Back to overview) DownPaper Actor(s): Charming Kitten DownPaper, sometimes delivered as sami.exe, is a Backdoor trojan. Its main functionality is to download and run a second stage. This malware has been observed in campaigns involving Charming Kitten, an Iranian cyberespionage group. References 2022-06-20 ⋅ ⋅ Infinitum IT ⋅ infinitum IT Charming Kitten (APT35) LaZagne DownPaper MimiKatz pupy 2017-12-05 ⋅ ClearSky Research Team Charming Kitten: Iranian Cyber Espionage Against Human Rights Activists, Academic Researchers and Media Outlets DownPaper 2017-12-01 ⋅ ClearSky ⋅ ClearSky Research Team Charming Kitten DownPaper Charming Kitten There is no Yara-Signature yet. Source: https://malpedia.caad.fkie.fraunhofer.de/details/win.downpaper https://malpedia.caad.fkie.fraunhofer.de/details/win.downpaper Page 1 of 1