HAMMERTOSS is a malware platform associated with Russian state-sponsored activity and commonly linked to APT29. It has been used in espionage operations and is notable for blending command-and-control and data theft activity with legitimate web services. Reported behavior includes the use of PowerShell for execution and the exfiltration of collected data by uploading it to actor-controlled accounts on web-based cloud storage providers, allowing operators to retrieve stolen information later while masking traffic within normal-looking internet services. The platform fits a stealth-focused intrusion model centered on covert execution, collection, and exfiltration rather than disruptive or financially motivated operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses PowerShell.
Uploads exfiltrated data to actor-created accounts on web cloud storage providers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.