FourteenHi is a previously unknown malware family/backdoor dubbed by Kaspersky in connection with a mid-March 2021 campaign that targeted governmental entities in the Russian Federation. The malware was deployed after exploitation of Microsoft Exchange Server zero-day vulnerabilities that were being widely abused at the time. Kaspersky reported traces of FourteenHi variants dating back about a year, indicating the family predated the observed March 2021 campaign. In related reporting on the ExCone campaign, Kaspersky stated that in July 2021 Russian government entities were targeted using VLC to deploy the FourteenHi backdoor after exploitation of Microsoft Exchange vulnerabilities. The activity showed overlaps in infrastructure and TTPs with HAFNIUM, and Kaspersky also noted ShadowPad use in the same timeframe. High-confidence details in the provided content identify FourteenHi primarily as a backdoor used in Exchange-exploitation-driven intrusions against Russian government targets; no further specific functionality or IoCs are provided in the source material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.