CHERRYSPY, also known as DownExPyer, is a custom espionage malware family associated with the Russia-aligned activity cluster TAG-110, tracked by CERT-UA as UAC-0063 and assessed with medium confidence to overlap with APT28. It has been used in intrusions targeting Ukrainian government and research entities and has also appeared in broader TAG-110 operations focused on public-sector organizations in Central Asia. The malware is deployed after initial compromise and is used as a follow-on payload for covert remote access and post-compromise operations.
Observed intrusion chains show CHERRYSPY delivered after spearphishing campaigns that use compromised email accounts and macro-enabled Microsoft Office documents as lures. In these operations, an initial HTA-based stage such as HATVIBE establishes command-and-control and persistence, after which operators deploy a Python runtime together with CHERRYSPY. A newer observed variant was compiled as a Python extension module in DLL form, differing from earlier pyArmor-obfuscated versions. Reporting also indicates TAG-110 has used multiple initial access vectors, including phishing and likely exploitation of CVE-2024-23692 in HFS HTTP File Server, after which CHERRYSPY may be introduced as a later-stage payload.
CHERRYSPY is part of a broader toolkit that includes HATVIBE, LOGPIE, STILLARCH, DownEx, and PyPlunderPlug. Its use is consistent with long-term cyber-espionage objectives against state bodies, research institutions, and other government-linked organizations. High-confidence reporting supports its role as a backdoor used for remote administration and follow-on post-exploitation activity on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...на комп'ютер в каталог "C:\ProgramData\Python" згодом завантажено Python-інтерпретатор та файл шкідливої програми CHERRYSPY, який, на відміну від попередньої версії, обфускованої за допомогою pyArmor, скомпільовано в .pyd (DLL) файл.
...на комп'ютер в каталог "C:\ProgramData\Python" згодом завантажено Python-інтерпретатор та файл шкідливої програми CHERRYSPY, який, на відміну від попередньої версії, обфускованої за допомогою pyArmor, скомпільовано в .pyd (DLL) файл.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Recorded Future's Insikt Group published research today detailing a Russia-aligned threat actor tracked as TAG-110 conducting espionage against government, educational, and research-related entities in Tajikistan.
На етапі первинного ураження зловмисник, маючи доступ до облікового запису електронної пошти співробітника установи, здійснив відправку копії нещодавно відправленого листа десяткам адресатів (включаючи самого відправника), замінивши оригінальний документ-вкладення іншим документом, в який було вбудовано макрос.
The A5 task results in a command execution... For example: A5(... command=['', '', '', 'taskkill /f /im pythonw.exe'])
Present with the files is a VBA macro that's responsible for placing the document template in the Microsoft Word startup folder for automatic execution and subsequently initiating communications with a command-and-control (C2) server and potentially executing additional VBA code supplied with C2 responses.
The A3 task is designed for file exfiltration... only files matching the specified criteria are collected.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware strain in the TAG-110/UAC-0063 espionage toolkit, used in attacks against Ukrainian state bodies and cited as a likely follow-on payload in later campaigns.
A malware family delivered later in TAG-110's phishing infection chain after macro-enabled Word documents establish persistence and command-and-control.
Custom malware family used by TAG-110 in espionage operations.
CHERRYSPY is a remote access trojan (RAT) used by UAC-0063 for hidden remote control of compromised computers. It is delivered alongside HATVIBE, often installed in the ProgramData directory with a Python interpreter, and compiled as a .pyd (DLL) file for stealth and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.