LOGPIE is a Windows keylogging malware associated with the espionage activity cluster tracked as UAC-0063 and TAG-110. It has been used in campaigns targeting government entities, diplomatic missions, and other public-sector organizations in Central Asia and Europe, including operations aligned with long-term intelligence collection. Reporting links its use to broader intrusion chains involving HATVIBE, CHERRYSPY, DownEx, and PyPlunderPlug.
LOGPIE is used to capture victim keystrokes, and more advanced variants have also monitored clipboard contents. Collected logs are written to local files and later retrieved through companion malware, particularly CHERRYSPY/DownExPyer tasking that exfiltrates and in some cases deletes harvested data. Observed operator activity indicates LOGPIE deployment may be prepared by installing Python dependencies on compromised hosts, consistent with the group’s broader use of Python-based tooling. Earlier related keylogging components also used scheduled-task persistence, and retrieval of LOGPIE log files has been directly observed in follow-on tasking.
LOGPIE appears in spearphishing-led intrusion chains that rely on weaponized Microsoft Word documents or macro-enabled Word templates using legitimate or themed government documents as lures. These initial documents establish command-and-control and persistence, then enable delivery of follow-on espionage tooling including LOGPIE. The malware’s role within these operations is focused on covert surveillance and collection of sensitive user input from compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CERT-UA's initial research on UAC-0063 describes an advanced variant of the analyzed script, the LOGPIE keylogger.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Present with the files is a VBA macro that's responsible for placing the document template in the Microsoft Word startup folder for automatic execution and subsequently initiating communications with a command-and-control (C2) server and potentially executing additional VBA code supplied with C2 responses.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware strain used by UAC-0063/TAG-110 in attacks against Ukrainian state bodies and referenced as part of the actor's espionage toolset.
A malware family delivered as a later-stage payload in TAG-110 phishing campaigns targeting Tajik institutions.
Custom malware family used by TAG-110 in espionage operations.
A more advanced keylogger variant associated with UAC-0063 that supports clipboard monitoring and stores logs with a .~tmp extension in a diagnostics-themed directory. DownExPyer A4 tasks were observed targeting those logs for exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.