Seduploader, also known as JHUHUGIT, is a Windows malware family associated with APT28/Sednit/Sofacy operations and commonly used as an early-stage reconnaissance and backdoor component in espionage intrusions. It has been delivered through spearphishing documents with malicious macros and through the SedKit exploit kit, and has also been observed executed via rundll32 as part of staged infection chains. The malware has been used for years in campaigns targeting government, defense, political, and other high-value organizations aligned with APT28 intelligence collection objectives.
Seduploader variants support host reconnaissance and surveillance functions including process enumeration, collection of network interface information, and screenshot capture. Some variants capture screenshots by simulating the screenshot key, retrieving the image from the clipboard, and converting it to JPG format. The malware also supports command-and-control communications that may use Base64-encoded POST data and resilient connectivity logic, attempting direct communication first, then proxy-aware communication, and in some cases falling back to browser process injection to maintain outbound access.
For persistence, Seduploader/JHUHUGIT has been observed registering itself as a scheduled task, installing itself as a Windows service, and using Registry Run-based autostart, including execution through rundll32 with JavaScript-based mechanisms. It also includes cleanup and anti-forensic functionality, with variants capable of self-deletion or deleting specified files. Overall, Seduploader is best characterized as a modular Windows backdoor and reconnaissance implant used by APT28 to establish footholds, profile victims, maintain persistence, and support follow-on espionage activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2017-10-19 ⋅ Proofpoint ⋅ APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed | 2017-10-19 ⋅ Proofpoint ⋅ APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed Seduploader
Analysis of the document revealed its end goal: dropping Sednit’s well-known reconnaissance tool, Seduploader. To achieve this, Sednit used two zero-day exploits: ... CVE-2017-0262 ... and ... CVE-2017-0263.
Analysis of the document revealed its end goal: dropping Sednit’s well-known reconnaissance tool, Seduploader. To achieve this, Sednit used two zero-day exploits: ... CVE-2017-0262 ... and ... CVE-2017-0263.
JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.
JHUHUGIT has exploited CVE-2015-1701 and CVE-2015-2387 to escalate privileges.
IoCs Table 2 lists a phishing document (f3805382ae2e23ff1147301d131a06e00e4ff75f) detected as Win32/Exploit.CVE-2016-4117.A; the report describes Sednit’s DealersChoice platform embedding Adobe Flash Player exploits in malicious Office documents.
Analysis of the document revealed its end goal: dropping Sednit’s well-known reconnaissance tool, Seduploader. To achieve this, Sednit used two zero-day exploits: ... CVE-2017-0262 ... and ... CVE-2017-0263.
The RTF attachment exploits the CVE-2015-1641 vulnerability to drop two DLLs on the system... This particular case is one among a series of attacks using the CVE-2015-1641 vulnerability launched from April 2016 by the Sednit group. | Seduploader serves as reconnaissance malware. It is made up of two distinct components: a dropper and the persistent payload installed by this dropper.
Seduploader serves as reconnaissance malware. It is made up of two distinct components: a dropper and the persistent payload installed by this dropper. | CVE-2015-2424 Microsoft Office 0-day at the time the Sednit group used it. Seduploader deployed with targeted phishing emails using a 0-day exploit for the Microsoft Office vulnerability CVE-2015-2424.
The JHUHUGIT implant became a relatively popular first stage for the Sofacy attacks and was used again with a Java zero-day (CVE-2015-2590) in July 2015. | JHUHUGIT (which is built with code from the Carberp sources)... its JHUHUGIT implant was delivered through a Flash zero-day and used a Windows EoP exploit to break out of the sandbox.
Table 3. Sedkit exploited vulnerabilities: CVE-2014-1510 / CVE-2014-1511 Firefox.
Table 3. Sedkit exploited vulnerabilities: CVE-2014-1510 / CVE-2014-1511 Firefox.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2012-0158 Microsoft Office.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2014-1761 Microsoft Word 0-day at the time the Sednit group used it.
The vulnerability CVE-2014-6332 was discovered in May 2014... Soon after the disclosure, a proof-of-concept was released... in October 2015 a simple revamped version of the original proof-of-concept was added to Sedkit. But the Sednit group went one step further in February 2016 by deploying a different exploit for this vulnerability.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2010-3333 Microsoft Office.
Table 3. Sedkit exploited vulnerabilities: CVE-2015-5119 Adobe Flash. Revamped from Hacking Team leaked data.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2013-2729 Adobe Acrobat Reader.
Table 3. Sedkit exploited vulnerabilities: CVE-2013-3897 Internet Explorer 8.
Table 1. Vulnerabilities exploited with targeted phishing attachments: CVE-2009-3129 Microsoft Excel.
CVE-2015-3043 Adobe Flash 0-day at the time Sedkit used it.
CVE-2015-7645 Adobe Flash 0-day at the time Sedkit used it.
Table 3. Sedkit exploited vulnerabilities: CVE-2013-1347 Internet Explorer 8.
CVE-2015-4902 Java 0-day at the time Sedkit used it.
Table 3. Sedkit exploited vulnerabilities: CVE-2014-1776 Internet Explorer 11.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2017-10-19 ⋅ Proofpoint ⋅ APT28 racing to exploit CVE-2017-11292 Flash vulnerability before patches are deployed Seduploader
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Titles such as “Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days” and “DealersChoice is Sofacy’s Flash Player Exploit Platform” describe browser/webmail-triggered exploitation.
Multiple entries describe APT28/Pawn Storm/Sofacy campaigns using lure documents, themed emails, and phishing schemes, e.g., “APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme”, “New Spear Phishing Campaign Pretends to be EFF”, and “distribution of emails with 'instructions' on 'updating the operating system'”.
Examples include “PowerPoint mouse-over event abused to deliver Graphite implants”, “BREXIT-themed lure document that delivers ZEKAPAB malware”, “fake NATO training docs to breach govt networks”, and repeated references to lure documents delivering Zebrocy or Seduploader.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
Here are some of the Seduploader features: ... Execution of code;
Many entries mention .bat, .cmd, or batch scripting, such as APT1 using batch scripting to automate execution, APT41 using a batch file for persistence, and numerous malware families executing or downloading batch files.
Unlike previous campaigns from this actor, the flyer does not contain an Office exploit or a 0-day, it simply contains a malicious Visual Basic for Applications (VBA) macro.
JHUHUGIT has used a Registry Run key to establish persistence by executing JavaScript code within the rundll32.exe process. Leviathan has used JavaScript to create a shortcut file in the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
COM Object hijack of the following CLSID: {BCDE0395-E52F-467C-8E3D-C4579291692E}, the CLSID of the class MMDeviceEnumerator.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
COM Object hijack of the following CLSID: {BCDE0395-E52F-467C-8E3D-C4579291692E}, the CLSID of the class MMDeviceEnumerator.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
The tools ... check for the existence of specific files, windows registry entries ... For example, SIG2 includes System\CurrentControlSet\Control\CrashImage and SIG23 includes software\microsoft\NetWin.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
JHUHUGIT tests if it can reach its C2 server by first attempting a direct connection, and if it fails, obtaining proxy settings and sending the connection through a proxy.
174 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
69 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader used extensively by APT28/Sofacy in spearphishing and exploit-driven espionage campaigns.
A first-stage loader delivered via spear phishing or SedKit as part of APT28's earlier implant chain.
Malware that injects its own functions into browser processes.
Gathers network interface card information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.