EnvyScout is a first-stage HTML smuggling dropper associated with the Russian cyberespionage group APT29, also tracked as NOBELIUM and Cozy Bear, and has been used since at least 2021 in diplomatic and government-focused intrusion campaigns. It is closely linked to espionage operations targeting foreign ministries, embassies, diplomatic missions, and other government-adjacent organizations, particularly in NATO and European Union countries.
The malware is typically delivered through spearphishing emails or lure documents that direct victims to a malicious HTML file or include that HTML file as an attachment. When opened, EnvyScout uses JavaScript to decode embedded payload data and write a disk image, commonly an ISO, to the victim system via HTML smuggling. The resulting image is intended to be opened by the user and commonly contains shortcut files and components used to launch additional malware. Observed infection chains have used deceptive shortcut execution, hidden DLL loading, proxy execution through Rundll32, and DLL sideloading with signed executables to run second-stage payloads.
EnvyScout functions primarily as a dropper for follow-on tooling rather than as a full-featured implant. Reported downstream payloads include Cobalt Strike and later-stage malware such as WINELOADER, as well as related APT29 toolchains involving components such as BoomBox, NativeZone, and VaporRage. Variants have also been observed using hidden files and directories to conceal malicious executables. In some campaigns, EnvyScout-supported chains contributed to persistence through subsequent payloads, but EnvyScout itself is best characterized as an initial delivery component in a broader espionage workflow.
The malware reflects APT29 tradecraft emphasizing socially engineered diplomatic lures, trusted or compromised web infrastructure, and delivery formats designed to reduce user suspicion and bypass common defenses. Its repeated use in embassy- and foreign affairs-themed campaigns makes it a notable element of modern Russian state-linked phishing and malware delivery operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"If the device targeted was an Apple iOS device, the user was redirected to another server under NOBELIUM control, where the since-patched zero-day exploit for CVE-2021-1879 was served."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Grupa ta wiązana jest m.in. z kampanią zwaną „SOLARWINDS”, narzędziami „SUNBURST”, „ENVYSCOUT” i „BOOMBOX”
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Questo CERT ha avuto evidenza oggi di una e-mail fraudolenta veicolata in Italia lo scorso 29 giugno. Il messaggio, che pretende di provenire da “Cancelliere governo.it” ... invita i destinatari a prendere visione dell’allegato PDF per una informativa inerente la vaccinazione COVID-19.
Il file HTML contiene uno script che ha il compito di acquisire l’indirizzo IP della vittima e lo User-Agent, di comunicarlo ad una pagina PHP ... e di rilasciare un file ISO
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
This file contains malicious JavaScript designed to create an .ISO file on the user’s computer.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The original HTML Smuggling attack conducted by Nobelium used EnvyScout to convert a text blob into an .ISO file.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
The content references collection of credential material from local systems, including "Bumblebee can capture and compress stolen credentials from the Registry and volume shadow copies," "GALLIUM collected ... password hashes from the SAM hive in the Registry," and "Windigo has used a script to gather credentials in files left on disk by OpenSSH backdoors."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Examples in the content include 'DropBook can unarchive data downloaded from the C2 to obtain the payload and persistence modules,' 'Molerats decompresses ZIP files once on the victim machine,' and 'Rocke has extracted tar.gz files after downloading them from a C2 server.'
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously reported malware/tool associated with NOBELIUM/APT29 in espionage campaigns.
A dropper used by APT29 since at least 2021.
HTML-based dropper used in initial access activity by APT29/Nobelium.
An HTML smuggling-based delivery script used to decode and download malicious files from compromised websites. The campaign used multiple evolving versions to hinder analysis.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.