Prikormka is a modular Windows cyber-espionage malware family associated with Operation Groundbait, a long-running surveillance activity active since at least 2008 and primarily focused on targets in Ukraine. The operation mainly targeted individuals rather than enterprises, including anti-government separatists in the Donetsk and Luhansk regions, as well as selected Ukrainian government officials, politicians, journalists, and nationalist figures. Prikormka is typically characterized as an espionage trojan with a plugin-based architecture that supports flexible tasking by operators.
Prikormka was distributed primarily through spearphishing emails carrying malicious attachments or links, often paired with decoy documents tailored to the victim’s political or professional interests. Some variants used screensaver-format executables and included checks intended to evade automated analysis. On infected systems, Prikormka established persistence through Registry Run entries and DLL search order hijacking, and it could be launched through rundll32.
Its core functionality included command-and-control communications, module download, and data exfiltration. Reported communications protections included Base64 encoding and Blowfish encryption for portions of command traffic. The malware’s modules supported credential theft from browsers and other applications, keylogging with foreground window context, screenshot capture, document theft, file and drive inventory collection, user and host profiling, network configuration discovery, and security software discovery. Additional modules enabled microphone recording, Skype call recording, geolocation based on nearby Wi-Fi data, and collection from removable media. Prikormka also gathered information such as the current username, IP and MAC addresses, installed antivirus products, available printers, and disk drives.
Prikormka is notable for its long operational history, modular design, and sustained use in politically motivated surveillance within the Russo-Ukrainian conflict environment. Later research identified multiple similarities between Operation Groundbait tooling and newer frameworks such as CommonMagic and CloudWizard, suggesting continuity or close relationship between the operators behind these espionage activities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware authors have also included a new value called roboconid, which represents the Operator’s ID. Our investigation allowed us to confirm that this ID is a unique number for the malware operator, who performs cyber operations and is assigned to infect, spy on, and track a particular target.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
When the user clicks on a malicious attachment that is masquerading as a document, the Prikormka dropper displays a decoy document in order to trick victims and distract their attention...
After encryption, the original (but not the encrypted) files are deleted.
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. Shared Modules), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
Agent Tesla can gather credentials from a number of browsers... APT33 has used a variety of publicly available tools like LaZagne to gather credentials... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge... SELECT action_url, username_value, password_value FROM logins; CryptUnprotectData
Agent Tesla can gather credentials from a number of browsers... APT3 has used tools to dump passwords from browsers... APT41 used BrowserGhost, a tool designed to obtain credentials from browsers, to retrieve information from password stores... TrickBot can obtain passwords stored in files from web browsers such as Chrome, Firefox, Internet Explorer, and Microsoft Edge
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
Thus, this simple check allowed the malware to bypass some sandboxes used for automatic sample processing.
The CORE module downloads additional components, which are used to harvest various types of data.
This module is responsible for collecting documents from removable media or fixed drives, connected via a USB interface.
The content is a catalog of malware families and threat actors that 'can perform keylogging,' 'log keystrokes,' 'capture keystrokes,' or use 'keylogger' modules/tools.
The communication is encrypted with the Blowfish cipher and then base64 encoded.
The DOWNLOADER module makes an HTTP request to one of its C&C servers... The communication is encrypted with the Blowfish cipher and then base64 encoded.
The DOWNLOADER module makes an HTTP request to one of its C&C servers, receives data, decrypts the data, saves it under the name hauthuid.dll and then loads the DLL.
329 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor with a module that collects the current username from the victim.
Collects victim IP and MAC address information.
Backdoor that encrypts some C2 traffic with Blowfish.
Backdoor with a module that collects victim IP and MAC address information.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.