EnvyScout, also known as ROOTSAW, is a first-stage HTML smuggling dropper used by APT29, also tracked as Nobelium and Cozy Bear, in cyberespionage operations since at least 2021. It has been used primarily in spearphishing campaigns targeting diplomatic personnel, foreign ministries, embassies, and other government-related organizations, especially in Europe and other regions aligned with Russian intelligence collection priorities.
EnvyScout is typically delivered as a malicious HTML attachment or via a link in a phishing lure that leads to a compromised website hosting the script. When opened, it uses JavaScript-based HTML smuggling to decode or deobfuscate an embedded payload and write a disk image, commonly an ISO file, to the victim system. The infection chain generally relies on user execution of the downloaded image and subsequent shortcut-triggered loading of malicious DLLs or sideloaded components, enabling delivery of follow-on malware.
The malware has been used to stage or deliver additional APT29 tooling including SNOWYAMBER, HALFRIG, QUARTERRIG, WINELOADER, and Cobalt Strike payloads. Reported tradecraft includes writing files to disk with JavaScript, deobfuscating embedded payload data, using hidden files and directories to conceal malicious executables, and collecting sensitive NTLM material from compromised Windows hosts. In observed campaigns, EnvyScout formed part of multi-stage intrusion chains that combined phishing, HTML smuggling, disk-image delivery, shortcut-based execution, and DLL sideloading to establish an initial foothold while reducing visibility to users and defenders.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"If the device targeted was an Apple iOS device, the user was redirected to another server under NOBELIUM control, where the since-patched zero-day exploit for CVE-2021-1879 was served."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Most of the recently-observed cases employed ENVYSCOUT, a delivery script APT29 has used since 2021, to lead to the downloads of SNOWYAMBER, QUARTERRIG, or HALFRIG.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Whichever strain of malware they attempted to distribute, attackers used phishing for initial access.
Il file HTML contiene uno script che ha il compito di acquisire l’indirizzo IP della vittima e lo User-Agent, di comunicarlo ad una pagina PHP ... e di rilasciare un file ISO
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
This file contains malicious JavaScript designed to create an .ISO file on the user’s computer.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The original HTML Smuggling attack conducted by Nobelium used EnvyScout to convert a text blob into an .ISO file.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A delivery script used by APT29 since 2021 to facilitate downloads of SNOWYAMBER, QUARTERRIG, or HALFRIG in phishing-based intrusion chains.
Previously reported malware/tool associated with NOBELIUM/APT29 in espionage campaigns.
A dropper used by APT29 since at least 2021.
HTML-based dropper used in initial access activity by APT29/Nobelium.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.