Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:21:24 UTC Home > List all groups > List all tools > List all groups using tool DELPHSTATS Tool: DELPHSTATS Names DELPHSTATS Category Malware Type Backdoor Description (Trend Micro) This backdoor is written in the Delphi programming language, and queries the C&C server for a .dat file before executing it via the Powershell.exe process. Similar to the SHARPSTATS backdoor, DELPHSTATS employs custom PowerShell script with code similarities to the one embedded into the SHARPSTATS backdoor. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool DELPHSTATS Changed Name Country Observed APT groups   MuddyWater, Seedworm, TEMP.Zagros, Static Kitten 2017-Jul 2025 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=474bae78-f701-472e-af2d-dc0f220f3967 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=474bae78-f701-472e-af2d-dc0f220f3967 Page 1 of 1