ESET Uncovers ACAD/Medre.A Worm: Tens Of Thousands Of AutoCAD Design Files Leaked in Suspected Industrial Espionage
SET, the leader in proactive protection celebrating 25 years of its technology this year, has uncovered a worm that targets drawings created in AutoCAD software for computer-aided design (CAD). Recently the worm, ACAD/Medre.A, showed a big spike in Peru on ESET’s LiveGrid® (a cloud-based malware collection system utilizing data from ESET users worldwide).

ESET’s research shows that the worm steals files and sends them to email accounts located in China. ESET has worked with Chinese ISP Tencent, Chinese National Computer Virus Emergency Response Center and Autodesk, the creator of AutoCAD, to stop the transmission of these files. ESET confirms that tens of thousands of AutoCAD drawings, primarily from users in Peru, were leaking at the time of the discovery. ESET has made a free stand-alone cleaner available at

“After some configuration, ACAD/Medre.A sends opened AutoCAD drawings by e-mail to a recipient with an e-mail account at the Chinese internet provider. It will try to do this using 22 other accounts at and 21 accounts at, another Chinese internet provider,” says ESET Senior Research Fellow Righard Zwienenberg.

“ACAD/Medre.A represents a serious case of suspected industrial espionage. Every new design is sent automatically to the operator of this malware. Needless to say this can cost the legitimate owner of the intellectual property a lot of money as the cybercriminals have access to the designs even before they go into production. They may even have the guts to apply for patents on the product before the inventor has registered it at the patent office,” adds Zwienenberg.

ACAD-Medre.A Pie Chart.png














ESET has made a free stand-alone cleaner available for public use. Upon the realization of the magnitude of this threat ESET reached out to Tencent, the owner of the domain.  ESET also established contact with Autodesk. Thanks to the swift actions of ESET and Tencent, the accounts used for relaying the e-mails with the drawings have been blocked and further leakage has been prevented.

ESET research teams around the globe have observed a small number of infections in other Latin American countries along with Peru. In addition, the high number of infections observed in Peru might also be explained by the fact that malware disguised as AutoCAD files may have been distributed to companies that were conducting business with public services in Peru. This leads us to think organizations in this country might have been the primary target of the ACAD/Medre.A operators. ESET is in contact with the local authorities to remediate the affected website.

“If there is one thing that becomes obvious from this piece of malware engaging in suspected industrial espionage is that reaching out to other parties to prevent further damage really works. Without the assistance of Autodesk, Tencent and Chinese National Computer Virus Emergency Response Center which helped ESET in taking down of dropsites and delivery chains, it would have been relatively easy only to clean already affected systems, but systems that would not be cleaned could have continued to be leaking their designs,” says ESET Chief Research Officer Juraj Malcho.

For more information about ACAD/Medre.A worm, please visit ESET Threat Center Blog.

ESET’s free stand-alone cleaner is available at: