HEADLACE is a modular, multi-component Windows backdoor used in Russian cyberespionage operations attributed to GRU-linked APT28, also tracked as Fancy Bear, Fighting Ursa, BlueDelta, and Forest Blizzard. Active in campaigns from at least 2023, it has targeted diplomatic, government, defense, logistics, critical-infrastructure, and policy-related organizations, particularly in Europe and Ukraine. HEADLACE is implemented through Windows command, batch, and Visual Basic Script components and serves as an early-stage implant for executing operator-supplied commands and follow-on payloads. Observed delivery chains use phishing or spearphishing lures, including malicious documents and ZIP archives masquerading as benign content. Some campaigns used DLL sideloading through a legitimate Windows executable to launch HEADLACE components. The backdoor abuses legitimate public web services and browser-mediated communications to retrieve tasking, execute commands, and return collected output, helping its traffic resemble ordinary web activity. Observed variants and related infection chains have used scheduled tasks for persistence and deleted staging or execution artifacts to reduce their forensic footprint. HOOKEDGE is assessed as a subsequent evolution of HEADLACE, sharing its batch-script execution model and browser-based communications tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Recorded Future research linked the activity to BlueDelta with moderate confidence and described HOOKEDGE as an evolution of the earlier HEADLACE backdoor.
The Russian GRU cyber campaign also involves malware such as HEADLACE and MASEPIE, which are used for persistence and data exfiltration.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A significant aspect of the campaign involves the exploitation of known vulnerabilities. The actors have weaponized multiple CVEs, including: CVE-2023-23397 in Microsoft Outlook to harvest credentials Roundcube vulnerabilities for email server access CVE-2023-38831 in WinRAR for remote code execution
The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.
The phishing attacks impersonate entities from several countries such as Argentina, Ukraine, Georgia, Belarus, Kazakhstan, Poland, Armenia, Azerbaijan, and the U.S., putting to use a mix of authentic publicly available government and non-government lure documents to activate the infection chains.
“In some cases, operators of the intrusion set attempted to establish a means of persistence by creating a scheduled task.”
These files include batch, command, VBScript, HTML, and XHTML components supporting execution, persistence, and exfiltration... Concatenates retrieved files into a .cmd payload and executes it.
Changes included modifications to lure documents and VBA obfuscation... Second-stage payloads retrieved by HOOKEDGE also share... base64 encoding schemes with payloads previously observed in HEADLACE campaigns.
Table 1 above shows that the first file IMG-387470302099.jpg.exe has a double file extension of .jpg.exe. Windows hosts with a default configuration hide file extensions, so the .jpg.exe file extension only shows as .jpg in the file name.
Finally, the batch file executes IMG387470302099.cmd, then deletes itself as a way to remove any obvious trace of malicious activity.
Throughout three phases, BlueDelta used phishing emails, legitimate internet services, and living-off-the-land binaries to extract intelligence from key networks across Europe.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
First, it checks if the visiting computer is Windows-based. If not, it redirects to a decoy image... As the final payload is Windows based, this operating system check is probably an effort to ensure that further actions taken in the attack are only taken for Windows visitors.
Uses a second Microsoft Edge instance to submit the collected information through an HTTP POST request to a separate exfiltration webhook.
HOOKEDGE routes command retrieval and data exfiltration through webhook[.]site using Microsoft Edge.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family/tool identified only as closely related to HOOKEDGE in this reference; no further functionality is described.
An earlier backdoor described as the predecessor from which HOOKEDGE evolved. No additional operational capabilities are provided.
An earlier backdoor from which HOOKEDGE is described as evolving. The content provides no further functional detail.
A previously documented BlueDelta Windows backdoor and apparent evolutionary predecessor to HOOKEDGE. The content states that it uses Windows batch scripting, legitimate internet services for C2 and exfiltration, and hidden browser instances for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.