HATVIBE is an HTA-based malware family used in cyber-espionage operations attributed to UAC-0063, also tracked as TAG-110, a cluster assessed by CERT-UA with medium to moderate confidence to overlap with APT28. It has been used primarily against government, diplomatic, research, and other public-sector targets in Ukraine, Central Asia, and parts of Europe, including campaigns affecting embassies and research institutions.
HATVIBE is commonly delivered through spearphishing documents that abuse Microsoft Office macros to reconstruct and launch an HTA payload via mshta.exe. In documented intrusions, attackers used trojanized or stolen legitimate-looking Word documents as lures, including documents resent from compromised email accounts, and established persistence through scheduled tasks that repeatedly invoked the HTA component. Reporting also indicates HATVIBE has been installed through exploitation of a public-facing application vulnerability, showing that the malware supports more than one initial access path.
Functionally, HATVIBE acts as a loader and backdoor for follow-on espionage activity. It profiles infected hosts and communicates with command-and-control infrastructure over HTTP, transmitting basic victim metadata and executing server-supplied tasking. Observed tasking included execution of returned code, VBScript execution, and file-dropping behavior. HATVIBE has been used to establish an initial foothold and persistent remote access before deployment of additional payloads, notably the Python-based CHERRYSPY implant, as well as tooling associated with file collection, screenshot capture, removable-media harvesting, and keylogging workflows. Its role in these operations is closely tied to long-term intelligence collection rather than disruptive effects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Слід додати, що в червні 2024 року зафіксовано численні випадки встановлення бекдору HATVIBE шляхом експлуатації вразливості (вірогідно, CVE-2024-23692) в програмному продукті HFS HTTP File Server | ...з використанням шкідливих програм HATVIBE та CHERRYSPY... буде створено ... HTA-файлу шкідливої програми HATVIBE "RecordsService"...
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
2024-12-31 ⋅ Maverits ⋅ APT28 the long hand of Russian interests MooBot STEELHOOK MASEPIE HATVIBE CredoMap Headlace OCEANMAP
...з використанням шкідливих програм HATVIBE та CHERRYSPY... буде створено ... HTA-файлу шкідливої програми HATVIBE "RecordsService"...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Слід додати, що в червні 2024 року зафіксовано численні випадки встановлення бекдору HATVIBE шляхом експлуатації вразливості (вірогідно, CVE-2024-23692) в програмному продукті HFS HTTP File Server...
Recorded Future's Insikt Group published research today detailing a Russia-aligned threat actor tracked as TAG-110 conducting espionage against government, educational, and research-related entities in Tajikistan.
На етапі первинного ураження зловмисник, маючи доступ до облікового запису електронної пошти співробітника установи, здійснив відправку копії нещодавно відправленого листа десяткам адресатів (включаючи самого відправника), замінивши оригінальний документ-вкладення іншим документом, в який було вбудовано макрос.
Previously, TAG-110 leveraged macro-enabled Word documents to deliver HATVIBE, an HTA-based malware, for initial access. The newly detected documents do not contain the embedded HTA HATVIBE payload for creating a scheduled task and instead leverage a global template file placed in the Word startup folder for persistence.
...буде створено та відкрито ще один документ (DOC) з макросом, який, у свою чергу, забезпечить створення на ЕОМ закодованого HTA-файлу шкідливої програми HATVIBE "RecordsService", а також, файлу запланованого завдання "C:\Windows\System32\Tasks\vManage\StandaloneService", призначеного для запуску останньої.
Once macros are enabled, the built-in subroutine Document_Open() is automatically executed. | the generated HTA file contains an encoded VBScript (VBE) payload to interact with the C2 server, receive commands, and execute malicious actions
After opening these documents, users encounter a deceptive display: blurred pages accompanied by a standard warning banner that 'Macros have been disabled.' This social engineering technique aims to pressure the user into enabling macros | These documents were all designed to deploy the HATVIBE loader using a combination of VBA scripts.
Previously, TAG-110 leveraged macro-enabled Word documents to deliver HATVIBE, an HTA-based malware, for initial access. The newly detected documents do not contain the embedded HTA HATVIBE payload for creating a scheduled task and instead leverage a global template file placed in the Word startup folder for persistence.
...буде створено та відкрито ще один документ (DOC) з макросом, який, у свою чергу, забезпечить створення на ЕОМ закодованого HTA-файлу шкідливої програми HATVIBE "RecordsService", а також, файлу запланованого завдання "C:\Windows\System32\Tasks\vManage\StandaloneService", призначеного для запуску останньої.
Previously, TAG-110 leveraged macro-enabled Word documents to deliver HATVIBE, an HTA-based malware, for initial access. The newly detected documents do not contain the embedded HTA HATVIBE payload for creating a scheduled task and instead leverage a global template file placed in the Word startup folder for persistence.
...буде створено та відкрито ще один документ (DOC) з макросом, який, у свою чергу, забезпечить створення на ЕОМ закодованого HTA-файлу шкідливої програми HATVIBE "RecordsService", а також, файлу запланованого завдання "C:\Windows\System32\Tasks\vManage\StandaloneService", призначеного для запуску останньої.
58 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool listed in APT28 reporting; exact function is not described in the provided content.
Backdoor delivered by APT28 using mshta.exe in fileless/LOLBin execution chains.
Malware used in UAC-0063-related campaigns; referenced in the context of embassy/European expansion and Kazakhstan targeting.
An HTA-based malware/loader previously used by TAG-110 for initial access, delivered via spear-phishing attachments and used to create persistence such as scheduled tasks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.