WasabiSeed is a custom downloader malware used in TA866 intrusion chains and described by Proofpoint and Cisco Talos as an intermediate stage for retrieving additional payloads from attacker-controlled infrastructure. It has been observed in financially motivated campaigns, with TA866 also known as Asylum Ambuscade and linked in reporting to both crimeware and possible espionage-related activity. Infection chains delivering WasabiSeed began with malspam, thread-hijacked emails, malicious attachments or URLs, PDF attachments containing OneDrive links, macro-enabled Publisher files, and malvertising or 404 TDS redirections. In observed chains, a JavaScript downloader retrieved an MSI package, which executed an embedded WasabiSeed VBS script such as OCDService.vbs or TermServ.vbs. WasabiSeed then downloaded and executed a second MSI payload, commonly Screenshotter, and continued polling in a loop for additional payloads. WasabiSeed established persistence by creating an LNK shortcut in the Windows Startup folder, including observed filenames such as OCDService.lnk. It randomized or keyed payload retrieval using the infected system’s C: drive serial number and contacted C2 endpoints such as hxxp://109[.]107.173.72/%serial% and hxxp://193[.]233.133.179/[C: Drive Serial Number]. Reporting states that TA866 frequently used WasabiSeed to deliver Screenshotter for victim triage and, in prior campaigns, follow-on payloads including AHK Bot and Rhadamanthys Stealer. Observed targeting associated with these campaigns was concentrated in the United States, with additional activity in Germany and broader follow-on victimology including manufacturing, government, and financial services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WasabiSeed effectively functions as another downloader stage that is used to retrieve additional payloads from attacker-controlled servers.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Typical distribution campaigns As previously mentioned, initial access to target environments is typically obtained by TA866 through successfully infecting systems via either malspam or malvertising.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
WasabiSeed is an MSI-delivered downloader stage that establishes persistence via a Startup LNK and continuously polls attacker infrastructure to retrieve and execute arbitrary MSI payloads.
A custom VBS-based downloader/backdoor component delivered via MSI. It executes in an infinite loop, polls a C2, and attempts to download and run additional MSI payloads (including the Screenshotter component in this campaign).
A VBS-based downloader/backdoor delivered via MSI that establishes persistence (Startup folder LNK) and repeatedly polls a C2 using Windows Installer to download and execute additional MSI payloads (e.g., Screenshotter, AHK Bot).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.