CEELOADER is a bespoke downloader/loader malware, described by Mandiant as written in C, that decrypts and executes shellcode payloads directly in memory on victim systems. It has been used both as an initial entry point and later to drop additional malware binaries. Reporting links its use to APT29/UNC2452 (also referred to by Microsoft as Nobelium and widely attributed to Russia’s SVR), including activity clusters UNC3004 and UNC2652. In observed intrusions, the actor used Cobalt Strike BEACON to persistently install CEELOADER as a Scheduled Task configured to run at user logon as SYSTEM on selected systems. The malware communicates over HTTP, with responses protected using AES-256-CBC. The surrounding campaigns targeted business and government entities globally, including diplomatic organizations, and often involved compromise of cloud service providers and downstream customers. High-confidence behavioral details in the content are limited to its role as a downloader/loader that decrypts shellcode for in-memory execution and its scheduled-task persistence in some APT29 intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CEELOADER : CEELOADER is a downloader that decrypts and executes shellcode payloads directly in memory on the victim’s device.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An in-memory downloader used by APT29 to decrypt and execute shellcode payloads, sometimes persisted via Cobalt Strike Beacon as a scheduled task.
A loader/dropper used as an initial foothold and to deploy additional malware payloads into victim environments.
Loader used to download and execute additional malware payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.