HeaderTip is a Windows malware family associated with activity tracked as UAC-0026 and publicly linked by some researchers to the Scarab espionage actor. It has been used in campaigns targeting Ukrainian organizations during the Russia-Ukraine conflict, including entities connected to critical information infrastructure. The malware is typically delivered through themed phishing lures using archive files that contain an executable loader and a decoy document impersonating Ukrainian government or law-enforcement material.
Operationally, HeaderTip functions as a lightweight first-stage implant with loader and backdoor characteristics. The initial executable drops auxiliary components, opens a decoy PDF to distract the victim, reconstructs a DLL payload from embedded data, and launches that DLL through standard Windows mechanisms. Persistence is established through user-level autorun entries so the malware survives reboots. The DLL payload is designed primarily to download and execute additional DLLs, enabling follow-on deployment of more capable malware such as trojans or rootkits.
HeaderTip uses several defense-evasion measures despite its relatively small size. Reported samples hide imports through stack strings, dynamically resolve APIs at runtime, and use hashed library and function names to complicate static analysis and signature-based detection. For command-and-control, the malware communicates over HTTP, including POST-based beaconing, and appears intended to await further tasking or secondary payloads rather than provide a broad standalone feature set.
Public reporting indicates similar activity dating back to at least 2020. Researchers have noted design and infrastructure overlaps between HeaderTip and earlier Scarab tooling, including possible lineage from the Scieron backdoor, though such attribution remains an analytic assessment rather than a universally established fact. Overall, HeaderTip is best understood as a compact persistent Windows loader/backdoor used in targeted intrusion operations for foothold establishment and follow-on malware delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Згаданий DLL-файл класифіковано як шкідливу програму HeaderTip, основним призначенням якої є завантаження та виконання інших DLL-файлів.
HeaderTip is a malware used by threat actor(s) that are leveraging the current Russia-Ukraine conflict to spread persistent malware. eSentire Threat Intelligence assesses with high confidence that HeaderTip serves as a backdoor and a loader for threat actor(s) to further deploy rootkits, trojans, or other types of malware.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
...а також DLL-файлу з видаленим MZ-заголовком "officecleaner.dat" та BAT-файлу "officecleaner.bat", що забезпечить формування коректного DLL-файлу...
In the case of the 2020 documents, the user must enable document Macros.
The threat actor(s) is using obfuscation techniques in the malware sample to hinder the analysis and avoid detection.
Upon analyzing the file in a disassembler, we have noticed that the malware is hiding the API imports by applying the stackstrings and dynamically resolving APIs at runtime.
...створення на комп'ютері документу-приманки "#2163_02_33-2022.pdf" (стосується листа Національної поліції України)...
The malware creates a POST request handle, checks if the request is successfully received from the C2 server with HTTP response code 200, and reads 128 bytes of data received from C2 server by calling InternetReadFile API.
31 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A persistent malware family used in a phishing campaign themed around the Russia-Ukraine conflict. It drops a BAT file and DLL, establishes persistence via Registry Run keys, uses obfuscation including stackstrings and API hashing, communicates with a C2 over HTTP on port 8080 using a DDNS domain, and appears to support in-memory DLL loading.
A custom 32-bit DLL backdoor used by Scarab. It is delivered via phishing lures and a loader/batch file chain, establishes persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and makes HTTP POST beacon requests to a C2 server. The report describes it as a limited first-stage infection waiting for possible second-stage payloads.
A named malware family associated with attacks on Ukrainian infrastructure.
A small 32-bit C++ DLL used by Scarab/UAC-0026 as a first-stage backdoor. It is installed via a loader and batch file, persists via HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and makes HTTP POST beacon requests to a C2 server while awaiting further updates or second-stage payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.