Seduploader is a reconnaissance malware family used in a campaign attributed by Cisco Talos to Group 74, also known as APT28, Fancy Bear, Sofacy, and Tsar Team. In the described October 2023 campaign, attackers targeted individuals interested in cybersecurity using a decoy Microsoft Word document, Conference_on_Cyber_Conflict.doc, themed around the Cyber Conflict U.S. conference. The document contained a malicious VBA macro rather than an Office exploit or zero-day. The macro extracted base64-encoded data from document properties, reconstructed a DLL, wrote it to disk as netwf.dat, and executed it via rundll32.exe using the KlpSvc export. The dropper then installed two hidden files, netwf.bat and netwf.dll, with netwf.bat used to execute the payload DLL. Persistence was established through HKCU\Environment\UserInitMprLogonScript and COM object hijacking of CLSID {BCDE0395-E52F-467C-8E3D-C4579291692E} (MMDeviceEnumerator). The payload could run via rundll32.exe or explorer.exe when the COM hijack was triggered. Reported Seduploader capabilities include screenshot capture via the GDI API, data and configuration exfiltration, code execution, and file downloading. The analyzed sample used myinvestgroup[.]com as command-and-control infrastructure. The report also notes updated constants intended to evade detection, including XOR key \x08\x7A\x05\x04\x60\x7c\x3e\x3c\x5d\x0b\x18\x3c\x55\x64 and mutex name FG00nxojVs4gLBnwKc7HhmdK0h. Reported IOCs include dropper hash 522fd9b35323af55113455d823571f71332e53dde988c2eb41395cf6b0c15805 and payload hash ef027405492bc0719437eb58c3d2774cc87845f30c40040bbebbcc09a4e3dd18.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The Seduploader Dropper is responsible for installing the Seduploader payload and establishing persistence on the victim system. It uses registry and COM hijacking techniques for persistence.
The Seduploader Dropper is responsible for installing the Seduploader payload and establishing persistence on the victim system. It uses registry and COM hijacking techniques for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.