WellMess is a lightweight backdoor malware family associated with APT29, also known as Cozy Bear and widely attributed to Russia’s SVR. It was publicly linked to cyber-espionage operations targeting organizations involved in COVID-19 vaccine research and development, as well as broader intelligence collection activity. The malware has been observed alongside the related WellMail implant and later in campaigns incorporating the Sliver command-and-control framework.
WellMess has been implemented in both .NET and Go, with Windows and Linux variants documented. The implants establish encrypted command-and-control sessions, collect host-identifying information, and allow a remote operator to execute commands and scripts on compromised systems. Reported functionality includes execution of PowerShell and shell scripts, file upload and download, collection of username and domain-related information, identification of privilege state and domain group membership, and exfiltration of data. Variants have also been described as capable of using DNS tunneling for command and control.
The malware uses layered protections and obfuscation for communications. Observed tradecraft includes RC6-encrypted host metadata, dynamically generated AES session keys protected with RSA, Base64-based encoding and obfuscation of C2 metadata, and mutual TLS in some variants. Victim metadata has been embedded in HTTP cookie fields to uniquely identify infected systems and communications. Linux variants have been observed with embedded certificate material to support secure communications.
WellMess is primarily an espionage-oriented implant rather than a destructive payload. It has been used to provide persistent remote access and post-compromise operational control on infected hosts, enabling operators to run scripts, transfer files, and collect system information from targeted environments. Documented targeting includes healthcare, pharmaceutical, research, government, diplomatic, think tank, and energy organizations, particularly where access could support Russian foreign intelligence objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT29 (Cozy Bear) атаковала организации, связанные с разработкой вакцины от COVID-19, через малварь WellMess и WellMail.
GRAVITYWELL, the Recorded Future designation for server technology and TLS certificate configuration commonly used to host the Russian Foreign Intelligence Service (SVR)-linked WellMess backdoor...
“…deployment of custom malware known as WellMess, WellMail, and Sorefang to target organizations involved in COVID-19 vaccine development.”
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The program is capable of encrypting, decrypting, uploading and downloading files. The malware can also execute commands and send and receive encrypted communications.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
Company Name Microsoft Corporation File Description Power Settings Command-Line Tool Internal Name powercfg.exe Original Filename powercfg.exe
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
Both collect the state of system privileges (disabled or enabled) from the infected system
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Displayed below is sample communication traffic between this WellMess implant and its C2 server. —Begin Sample Network Traffic— POST / HTTP/1.1 ... Cookie: ... | These implants allow a remote operator to establish encrypted command and control (C2) sessions... The function appears to be the main export of the DLL, which initiates a C2 session with the implants remote C2 server at the Internet Protocol (IP) address, 85.93.2.116.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
When the file is executed, it attempts to create a C2 connection to one of the following IP addresses: 141.98.212.55 over Transmission Control Protocol(TCP) Port 53 209.58.186.196 over TCP Port 443
Both versions also allow an operator to pass AES encrypted executable scripts to infected systems... The malware can receive and parse messages from the remote operator.
C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
"communicate with C2 over mutual TLS"; "client and server mutually check certificates"; "can use mutual TLS and RSA cryptography to exchange a session key". | Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WellMess is cited as malware used by APT29 in a certificate-based infrastructure tracking example.
Their toolkit includes ... TrailBlazer, WellMail, WellMess, WINELOADER and Living off the Land.
Custom malware attributed to SVR, historically used to target COVID-19 vaccine development organizations; authorities also state it was used against energy sector companies.
SVR-linked backdoor associated with transient GRAVITYWELL infrastructure that shifted after public reporting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.