FILEMESS
FILEMESS is a Go-based stealer used in Ukrainian-targeted campaigns, particularly those attributed by CERT-UA to UAC-0239. Since at least the second half of September 2025, it has been observed in spearphishing attacks against the Defence Forces of Ukraine and local government/state bodies across multiple Ukrainian regions, including campaigns impersonating the Security Service of Ukraine and using lure themes related to “countering russian sabotage-reconnaissance groups.” Delivery was observed via phishing emails sent from services such as UKR.net and Gmail, with links to password-protected archives or direct VHD attachments containing an executable and decoy PDF documents. FILEMESS was also reported alongside the OrcaC2 framework.
Its primary function is file theft. FILEMESS recursively searches for files matching targeted extensions in Desktop, Downloads, and Documents folders and on logical drives D through Z; reporting also notes that it collects files matching certain extensions and exfiltrates them to Telegram via the Telegram API. It computes MD5 hashes of discovered files, uses two extension lists including a shorter list for common user folders, checks for an existing process to avoid multiple concurrent instances, and establishes persistence through a Windows Registry Run key. Its Telegram API credentials are XOR-obfuscated and Base64-encoded. High-confidence associations in the provided content link FILEMESS to UAC-0239 campaigns targeting Ukrainian defense forces and local governments; no specific file hashes or network IoCs for FILEMESS itself were provided in the content.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
14.10.2025 "Протидія російським ДРГ": UAC-0239 здійснює кібератаки з використанням фреймворку OrcaC2 та стілеру FILEMESS (CERT-UA#17691)
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used in campaigns targeting Ukraine.
Go-based file stealer delivered via phishing (VHD lure) that searches for files matching specific extensions and exfiltrates them to Telegram.
Referenced as a stealer used alongside the OrcaC2 framework in cyberattacks.
File-stealing malware that recursively searches for files with specified extensions in user folders (Desktop/Downloads/Documents) and logical drives (D–Z), computes MD5 hashes, and exfiltrates files via the Telegram API. Uses XOR-obfuscated and Base64-encoded Telegram API credentials, adds a Run key for persistence, and checks for an existing process to avoid multiple concurrent instances.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.