Ostap
Ostap is a malware downloader/loader used in email-borne infection chains. The provided content describes it as a downloader that uses JavaScript to hide itself from security sandbox analysis tools, and also references OSTap-style macro execution, payload download behavior, and a JavaScript variant. Proofpoint reporting cited in the content associates Ostap with TA800, a cybercrime actor that has delivered first-stage malware including The Trick, BazaLoader, Buer Loader, and Ostap. In this context, Ostap is part of the initial-access ecosystem that enables follow-on malware deployment and can contribute to ransomware intrusion chains, although the content does not establish a one-to-one relationship between Ostap and a specific ransomware family. The available material indicates delivery via malicious files and macro-enabled documents, with JavaScript-based evasion behavior aimed at defeating sandbox analysis. No high-confidence IOCs are provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This threat actor attempts to deliver and install banking malware or malware loaders including The Trick, BazaLoader, Buer Loader, and Ostap.
"The group also uses Ostap, a malware downloader that uses JavaScript to hide itself from security sandbox analysis tools."
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader delivered by TA800 as part of initial access activity.
Downloader used to fetch/execute additional payloads; noted for JavaScript-based evasion against sandbox analysis.
OSTap is a malware loader known for delivering secondary payloads, often via malicious macros in Office documents. It is commonly used to download and execute other malware, such as banking trojans or ransomware.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.