ROOTSAW, also publicly referred to as EnvyScout, is an HTML/JavaScript dropper used by APT29 (Cozy Bear / Midnight Blizzard), a cyberespionage group attributed to Russia’s SVR. The malware is described as a central component of APT29’s initial access operations for foreign political intelligence collection. Beginning as early as 26 February 2024, APT29 used phishing campaigns with attachments containing links to an actor-controlled compromised website, including waterforvoiceless[.]org/invite.php, which redirected victims to a ROOTSAW dropper. ROOTSAW then requested the download and execution of second-stage malware including WINELOADER; related reporting also notes APT29 used ROOTSAW delivery mechanisms and victim filtering in July 2023 to deploy ICEBEAT against European diplomatic entities.
Technically, ROOTSAW is described as a dropper HTML file containing JavaScript. It has been reported to XOR- and Base64-decode an embedded ISO/IMG file for execution. In the 2024 activity, the ROOTSAW variant used JavaScript obfuscation consistent with prior APT29 operations. The payload, when parsed, downloaded a file to disk as invite.txt, used Windows Certutil to decode it, used tar to decompress the decoded content, and executed the legitimate Windows binary SqlDumper.exe as part of the infection chain.
APT29 has used ROOTSAW in spearphishing operations targeting diplomatic entities in Europe, North America, and Asia, and reporting cited here specifically states the malware was expanded to target German political parties, reflecting SVR interest in political and civil society intelligence. The broader targeting context associated with APT29 includes governments, diplomatic organizations, and related entities. High-confidence infrastructure and artifacts directly mentioned for ROOTSAW activity include waterforvoiceless[.]org/invite.php and waterforvoiceless[.]org/util.php, the downloaded filename invite.txt, and the use of Certutil, tar, and SqlDumper.exe during execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beginning on February 26, 2024, APT29 launched phishing campaigns with attachments containing links to a compromised, actor-controlled website, which redirected victims to a ROOTSAW dropper. This dropper then requested the download and execution of the second-stage WINELOADER.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader referenced as used by APT29 in invitation-themed phishing to deploy malicious payloads against political/government targets in Europe.
A dropper used in APT29 phishing campaigns to fetch and execute second-stage payloads, specifically WINELOADER.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.