WellMail is a lightweight custom malware family associated with APT29, also known as Cozy Bear or The Dukes, and has been publicly linked to Russian state-sponsored cyberespionage activity. It has been observed alongside WellMess in operations targeting organizations involved in COVID-19 vaccine research and development, as well as broader espionage activity against government, diplomatic, healthcare, energy, and related sectors.
WellMail is written in Go and functions as a backdoor used for post-compromise operations. It supports encrypted command-and-control communications, including mutual TLS using embedded client and certificate authority material, and can also communicate over TCP. The malware enables remote operators to execute commands and dynamically run scripts received from command and control after decompressing them. It can upload and download files, archive files on compromised hosts, and exfiltrate data from victim systems.
In addition to remote tasking and file operations, WellMail performs basic host profiling by identifying the current username and the victim system’s IP address. These capabilities support operator situational awareness and victim management during intrusions. Public reporting has consistently placed WellMail within APT29 tradecraft as a bespoke espionage implant rather than commodity malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In these campaigns, the group used two custom malware families, WellMess and WellMail.
“…deployment of custom malware known as WellMess, WellMail, and Sorefang…”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Most cyber activity by malicious actors requires infrastructure like servers on the internet. Some APT groups used several thousand Command and Control (C2) servers over the years. | Also, this article covers only HTTP(S) based infrastructure.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
"...send the above data to its C2 server at the IP address, 119.81.184.11:25 over TCP port 25..."; "Note: TCP port 25 is commonly used for email (SMTP), however, the malware is only using the port for secure communications"
The content repeatedly describes malware and threat actors using SSL, TLS, HTTPS, RSA, AES, Blowfish, RC4, ECIES, Diffie-Hellman, OpenSSL, WolfSSL, and mutual TLS to protect command and control traffic.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2"). | "communicate with C2 over mutual TLS"; "client and server mutually check certificates"; "can use mutual TLS and RSA cryptography to exchange a session key".
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WellMail is cited alongside WellMess as malware used by APT29 in a certificate-based infrastructure tracking example.
Their toolkit includes ... TEARDROP, TrailBlazer, WellMail, WellMess, WINELOADER...
Custom malware attributed to SVR, referenced in the context of targeting COVID-19 vaccine development organizations; also stated to have been used against energy sector companies.
Backdoor that can identify the current username on the victim system.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.