GraceWire is a Trojan/malware implant observed in financially motivated intrusion chains. It has been associated with FIN7, which Microsoft tracks as Sangria Tempest and which is also referenced as ELBRUS/Carbon Spider, and it has also been listed among malware distributed by GOLD TAHOE (TA505/FIN11). Reported delivery chains include the Get2 loader, Carbanak, and POWERTRASH; Microsoft also reported Sangria Tempest using Storm-1113's EugenLoader delivered through malicious MSIX/App Installer campaigns to inject Carbanak, which then delivered the GraceWire implant. POWERTRASH has also been used to load NetSupport and GraceWire. The malware has appeared in phishing and malvertising-driven campaigns, including COVID-19-themed phishing where macro-enabled Excel documents installed Get2, which then loaded GraceWire. The available content states that Trojans such as GraceWire often download additional malware including RATs, desktop-sharing clients, and ransomware. GOLD TAHOE-related reporting says malware including GraceWire was used to facilitate lateral movement within victim networks. Microsoft further states that GraceWire is typically affiliated with Lace Tempest and that Sangria Tempest has cooperated with Lace Tempest in past intrusions. A detection reference in the provided content lists Win32/GraceWire dated March 2019.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since late 2018, GOLD TAHOE focused largely on distributing their own malware such as Get2, SDBbot, GraceWire, TrueBot, and FlawedAmmy...
...inject Carbanak – a piece of software that the group has used for a decade to deliver the Gracewire implant.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A post-exploitation implant delivered via Carbanak in FIN7 intrusions, used for persistent access and follow-on operations (specific capabilities not detailed in the content).
Malware implant delivered via Carbanak or loaded via POWERTRASH in Sangria Tempest activity; associated in the text with Lace Tempest affiliation.
Malware distributed by GOLD TAHOE and used to facilitate lateral movement within victim networks.
Win32/GraceWire [[URL_b3187638_222]] 2019 年 3 月 (5.70)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.