HEADLACE is a modular, multi-component Windows backdoor associated with the Russian GRU-linked APT28 intrusion set, also tracked as Fancy Bear, BlueDelta, Fighting Ursa, Forest Blizzard, and ITG05. Active in espionage operations since at least 2023, it has targeted diplomatic, government, defense, logistics, energy, and policy-related organizations across Europe, Ukraine, and other countries. It is commonly delivered through targeted phishing campaigns using weaponized documents, links, or archives with topical and diplomatic lures. Execution chains have used Windows batch, command-shell, and VBScript components; legitimate executables for DLL sideloading; Microsoft Edge for browser-mediated communications; and public web services for command staging and result transmission. HEADLACE retrieves and executes follow-on command payloads, can collect and transmit command output and reconnaissance data, and has been used to support persistence and data exfiltration. Variants remove installation or temporary artifacts and may use hidden or headless browser execution to reduce visibility. The malware is part of APT28's adaptable initial-access and collection toolkit and is the predecessor of the related HOOKEDGE backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HOOKEDGE shares substantial architectural and code similarities with the group’s previously documented HEADLACE backdoor, including Windows batch-based execution, abuse of legitimate internet services, and browser-mediated C2 communications.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”
These files include batch, command, VBScript, HTML, and XHTML components supporting execution, persistence, and exfiltration... Concatenates retrieved files into a .cmd payload and executes it.
Changes included modifications to lure documents and VBA obfuscation... Second-stage payloads retrieved by HOOKEDGE also share... base64 encoding schemes with payloads previously observed in HEADLACE campaigns.
Table 1 above shows that the first file IMG-387470302099.jpg.exe has a double file extension of .jpg.exe. Windows hosts with a default configuration hide file extensions, so the .jpg.exe file extension only shows as .jpg in the file name.
Finally, the batch file executes IMG387470302099.cmd, then deletes itself as a way to remove any obvious trace of malicious activity.
Throughout three phases, BlueDelta used phishing emails, legitimate internet services, and living-off-the-land binaries to extract intelligence from key networks across Europe.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
Uses a second Microsoft Edge instance to submit the collected information through an HTTP POST request to a separate exfiltration webhook.
HOOKEDGE routes command retrieval and data exfiltration through webhook[.]site using Microsoft Edge.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously documented BlueDelta Windows backdoor and apparent evolutionary predecessor to HOOKEDGE. The content states that it uses Windows batch scripting, legitimate internet services for C2 and exfiltration, and hidden browser instances for C2 communications.
Backdoor présenté comme le prédécesseur direct de HOOKEDGE; aucune fonctionnalité supplémentaire n’est décrite dans ce contenu.
An earlier backdoor associated with the same actor; HOOKEDGE is described as its evolution and shares batch-scripting and browser-based communications characteristics.
A BlueDelta backdoor from prior campaigns. The content identifies deep code and structural overlap with HOOKEDGE, including identical JavaScript variable names and the same Base64 encoding scheme for automated downloads; HOOKEDGE is assessed as its direct evolutionary successor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.