SEAWEED is a custom Trojan/backdoor used by the Iranian-linked espionage group APT39. Reporting cited here describes it as one of APT39’s primary backdoors, alongside CACHEMONEY and a unique POWBAT variant, used post-compromise to establish and maintain a foothold in victim environments. APT39 has been tracked targeting telecommunications, travel, and technology services organizations, with broader reporting also noting government targeting. The group’s operations are assessed as focused on intelligence collection, including monitoring, tracking, and surveillance of specific individuals, as well as theft of personal information such as travel itineraries and telecommunications-related customer data. In the described intrusion lifecycle, APT39 commonly gains initial access via spearphishing with malicious attachments or links, exploitation of vulnerable web servers to deploy web shells such as ANTAK and ASPXSPY, and use of stolen credentials to access externally facing Outlook Web Access resources. After compromise, SEAWEED is deployed as part of the group’s custom malware set, while operators also use legitimate and publicly available tools including Mimikatz, Windows Credential Editor, ProcDump, and Ncrack; custom reconnaissance tooling such as BLUETORCH; lateral movement mechanisms including RDP, SSH, PsExec, RemCom, and xCmdSvc; and custom SOCKS5 proxy tools REDTRIP, PINKTRIP, and BLUETRIP. No SEAWEED-specific indicators of compromise are provided in the source content beyond its association with APT39.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Post-compromise, APT39 leverages custom backdoors such as SEAWEED, CACHEMONEY, and a unique variant of POWBAT...
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.