Downdelph is a lightweight downloader/backdoor developed in Delphi and associated with the Sednit/APT28/Fancy Bear/Sofacy intrusion set. Reporting places it within Sednit’s broader malware ecosystem alongside tools such as Xagent, Sedreco, Seduploader, Xtunnel, Usbstealer, and Zebrocy. It has been described as being deployed by APT28 together with a bootkit/rootkit to ensure persistence on victim systems, and HIDEDRV has been reported injecting a DLL for Downdelph into explorer.exe.
Observed behavior includes privilege escalation and defense evasion on Windows. Downdelph bypasses UAC using a custom "RedirectEXE" shim database, and it has also been reported to use search-order hijacking of sysprep.exe to escalate privileges. For command-and-control, Downdelph uses RC4 to encrypt C2 responses and inserts pseudo-random characters between original characters when encoding C2 network requests, complicating signature creation and protocol analysis.
The malware is tied to APT28/Sednit espionage operations that have broadly targeted government, diplomatic, military, and geopolitically relevant entities, particularly in Eastern Europe and other high-value government-related sectors. High-confidence aliases in the provided content include Delphacy.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the Downdelph bootkit and rootkit (described in the third part of this whitepaper).
7 distinct techniques documented for this family, organized by ATT&CK tactic.
"AppleJeus ... has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence." / "APT41 ... has used search order hijacking to execute malicious payloads" / "Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons."
APT28 has deployed a bootkit along with Downdelph to ensure its persistence on the victim. The bootkit shares code with some variants of BlackEnergy.
"AppleJeus ... has also used DLL search order hijacking via the IKEEXT service, running with LocalSystem privileges, to load the TAXHAUL DLL for persistence." / "APT41 ... has used search order hijacking to execute malicious payloads" / "Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons."
"3PARA RAT command and control commands are encrypted within the HTTP C2 channel using the DES algorithm in CBC mode..."; "APT33 has used AES for encryption of command and control traffic."; "Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode)."; "Duqu ... data stream can be encrypted with AES-CBC."; "PoisonIvy uses the Camellia cipher to encrypt communications."
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28 malware used alongside a bootkit to maintain persistence on victim systems.
An older Sednit/APT28 Delphi-based downloader delivered via email attachments; appears to have been phased out around late 2015 as Zebrocy emerged.
Bypasses Windows UAC for privilege escalation using a custom RedirectEXE application-compatibility shim database.
Malware that escalates privileges by bypassing UAC using a custom RedirectEXE shim database.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.